EST · MMXXVI
Home/Jurisdictions/Czech Republic/EMI onboarding for vasps in Czech Republic
Banking, Payments & EMI Onboarding

EMI onboarding for vasps in Czech Republic

Emi onboarding for vasps in Czech Republic. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Operating a virtual asset service provider (VASP) without a functioning fiat corridor is not a strategic problem – it is an existential one. In the Czech Republic, where a maturing payment licence environment sits alongside a transitioning crypto banking regime, the question facing most inbound digital-asset businesses is not whether they need fiat rails, but which electronic money institution (EMI) will actually open an account for them and on what regulatory basis.

Czech Republic crypto law is in motion. The country has incorporated EU anti-money-laundering directives and is transitioning its prior VASP registration regime toward full MiCA CASP authorisation under ESMA oversight, with the Czech National Bank (ČNB) acting as the national competent authority. For an inbound operator, the practical challenge is managing that transition while simultaneously securing fiat rails – the EMI onboarding process that turns a licensed structure into a working business. This page sets out the regulated basis, the process, the cross-border banking reality and the decision point.

What is the regulated basis for VASP banking in the Czech Republic?

EMI onboarding for VASPs in the Czech Republic rests on two overlapping regulatory pillars: the Czech National Bank's supervision of payment institutions and electronic money institutions, and the EU-level MiCA regime now governing crypto-asset service providers. A VASP operating in or from the Czech Republic must satisfy both the payment-services regulator and any prospective EMI that its own licensing, AML programme and control environment meet the required standard.

The Czech National Bank supervises payment institutions and EMIs under the transposed EU Payment Services Directives. An EMI licensed in the Czech Republic, or passporting into it from another EU member state, must conduct its own due diligence on every business customer. For VASPs, that due diligence is structurally more demanding than for a conventional e-commerce merchant. The EMI must satisfy itself about the VASP's licensing status, the jurisdictions it serves, its AML/KYC programme, its beneficial ownership structure and its exposure to high-risk counterparties.

MiCA adds a second layer. A VASP seeking CASP authorisation under the MiCA regime must demonstrate, as part of its application, that it has appropriate arrangements for holding client funds. The ČNB, as national competent authority, will expect to see that fiat flows are handled through a supervised payment institution. The circularity is real: the regulator expects a banking arrangement before authorisation, while the EMI requires evidence of regulatory progress before onboarding. Managing that sequencing is the core planning problem.

In our practice, we regularly advise VASPs navigating this loop in Central European jurisdictions. The practical solution is almost always a staged approach: secure a preliminary account commitment from an EMI in parallel with the CASP application, using the application itself as compliance evidence.

Which EMIs actually onboard VASPs operating in the Czech Republic?

The EMI market relevant to Czech-based VASPs spans domestic Czech payment institutions, EU-passporting EMIs from Lithuania, Malta and other member states, and a small number of specialist digital-asset-friendly payment providers. Each category carries a different risk appetite, onboarding timeline and ongoing compliance burden.

Domestic Czech payment institutions tend to apply the most conservative risk appetite toward VASPs. The ČNB's AML expectations are well-enforced, and domestic institutions are acutely aware of the reputational and supervisory risk of misclassifying a digital-asset counterparty. Onboarding timelines vary considerably, but operators should not expect a rapid process at a domestic bank – the review of a VASP's AML programme alone can extend the timeline materially.

EU-passporting EMIs, particularly those licensed by the Bank of Lithuania and operating under the EU's single-passport mechanism, have historically offered more accessible onboarding for VASPs. Lithuania's regulator has developed detailed supervisory expectations for crypto-facing payment institutions, which paradoxically produces EMIs that understand the VASP risk profile better than generalist institutions. The trade-off is that passporting EMIs often impose transaction-volume limits and enhanced monitoring that a scaling exchange will eventually outgrow.

Specialist digital-asset payment providers, including a small number of non-bank payment institutions focused exclusively on the sector, offer the most crypto-native onboarding experience. They are, however, fewer in number, subject to higher correspondent-banking pressure themselves, and may carry their own jurisdictional limitations on which currencies or corridors they can support.

The right EMI choice depends on the VASP's transaction profile, its licensing stage and its medium-term growth plan. We map that decision as part of the initial structure review – before any formal approach is made.

The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. For a scoped assessment of your EMI onboarding situation in the Czech Republic, contact OBOLUS at info@oboluslaw.com.

What does an EMI require from a VASP applicant?

An EMI conducting due diligence on a VASP applicant is, in substance, performing a compressed regulatory review of the VASP's entire compliance posture. The documentation and process demands go well beyond a standard corporate account opening and routinely surface gaps that the VASP's own counsel has not yet addressed.

The core package an EMI will require typically covers: evidence of applicable licensing or registration (including the CASP application status under MiCA, or the prior Czech VASP registration); the VASP's AML/CFT policy and procedures; the VASP's Travel Rule compliance framework (the obligation to transmit originator and beneficiary data with virtual-asset transfers, as required under FATF Recommendation 15 and its EU implementation); the identity of ultimate beneficial owners and a group structure chart; a business plan covering anticipated transaction volumes, customer base and jurisdictions served; a description of the VASP's own customer due diligence procedures; and, increasingly, evidence of an independent AML audit or an MLRO appointment.

In our cross-border practice, the Travel Rule documentation is the most frequent sticking point. Many VASPs have a policy in name but cannot demonstrate operational compliance – that is, they cannot show how the Travel Rule data is collected, transmitted and received in practice. An EMI's compliance team will probe this in detail, and a vague answer will stall or kill the application.

Beneficial ownership verification is a second consistent friction point. Czech and EU AML rules require the EMI to identify every natural person owning or controlling more than a defined threshold of the VASP. For VASPs with complex holding structures – common where the entity was incorporated offshore for tax or regulatory reasons – that exercise can take weeks and may require re-structuring before onboarding proceeds.

The VASP's exposure to sanctioned jurisdictions, sanctioned individuals and high-risk counterparties will receive close attention. An EMI operating under ČNB supervision cannot carry a customer whose transaction flow creates material sanctions exposure. The VASP must demonstrate not only that it screens counterparties but that it has the technical infrastructure to do so in real time.

How does the cross-border structure affect EMI onboarding?

The jurisdiction where a VASP is incorporated, where it holds its licence, where its clients are located and where its banking sits are four distinct questions – and misalignment among them is the most common reason an EMI onboarding application fails or produces an account with severe restrictions.

A VASP incorporated in the BVI or Cayman Islands but operating its exchange business from a Czech entity, serving EU retail clients, faces a specific set of tensions. The offshore holding structure may be commercially sensible. But the EMI – particularly a Czech or Lithuanian institution – will apply EU AML standards to the whole group. If the beneficial ownership chain runs through a jurisdiction the EMI's correspondent bank treats as high-risk, the application will stall regardless of the Czech entity's own clean record.

The MiCA passporting mechanism reshapes this dynamic for VASPs that obtain CASP authorisation in one EU member state. Once authorised, a CASP may passport its services across the EU/EEA, making the Czech market accessible without a separate Czech licence. The banking question does not disappear – the CASP still needs a Czech or EU-passporting payment account – but the regulatory footprint simplifies materially. VASPs planning for scale should model the full licensing and banking stack across the operating, custody and payment layers before committing to a structure.

Tax sits beneath all of this. The Czech Republic imposes corporate income tax and VAT on financial services, with crypto-specific treatment continuing to evolve as domestic guidance catches up with MiCA. A VASP that routes revenue through a Czech entity without adequate transfer-pricing documentation, or that treats digital-asset gains as outside the Czech tax net without legal basis, may face a challenge that also surfaces in the EMI's business-plan review. The EMI's compliance team is not a tax authority, but it will ask how the business makes money and where that money is taxed.

In one recent matter, a payments company had structured its EU operations through a Czech entity with a Lithuanian EMI account. The EMI suspended the account following a correspondent-banking review that flagged the company's exposure to a wallet cluster associated with a high-risk exchange. We worked with allied counsel in the relevant jurisdiction to document the VASP's screening controls, obtain a forensic transaction analysis and present a remediation plan to the EMI's compliance team. The account was reinstated within a defined review period and the company subsequently progressed its CASP pre-application filing with the ČNB. The lesson: EMI relationships require active maintenance, not just a successful opening.

What mistakes do VASPs make in the EMI onboarding process?

The single most common error is approaching an EMI too early – before the VASP's compliance infrastructure is genuinely ready for scrutiny. An EMI rejection, or a withdrawal mid-process, is recorded. Subsequent applications to other institutions will be harder to progress if the VASP cannot explain why the prior approach did not succeed.

A second frequent mistake is treating the EMI application as separate from the licensing application. In reality, the two processes share significant documentary overlap and a credible CASP pre-application strengthens the EMI approach materially. Operators that sequence them in parallel, using a unified compliance pack, consistently achieve better outcomes than those that treat banking as an afterthought to licensing.

Third: underestimating the Travel Rule operational gap. A VASP that has a written policy but no implemented VASP-to-VASP data exchange protocol will be exposed in an EMI's compliance review. The EMI's own Travel Rule obligations mean it cannot onboard a VASP that cannot demonstrate compliance.

Fourth: failing to anticipate the correspondent-banking dimension. The EMI's own access to SWIFT rails, EUR SEPA corridors and USD correspondent accounts depends on its own compliance standing. If the VASP's transaction profile – high-volume, multi-jurisdictional, with exposure to peer-to-peer wallets – is one the EMI's correspondents flag, the EMI may decline even a structurally compliant VASP. Understanding which corridors the target EMI actually controls, before applying, is a significant advantage.

How do you assess whether your VASP is ready for EMI onboarding?

Readiness for EMI onboarding in the Czech Republic is a function of five measurable factors. Working through them honestly before making an approach reduces the risk of a failed application and the reputational cost that follows.

First, licensing status. Is the VASP registered or authorised under the applicable Czech or EU regime? For an entity in the MiCA transition period, does it have a credible CASP pre-application in progress? An EMI will place weight on regulatory progress even where full authorisation is not yet obtained.

Second, AML programme quality. Is the AML/CFT policy current, jurisdiction-specific and operationally implemented? Does the VASP have an appointed MLRO, a documented risk assessment and a record of completed customer due diligence? Has the programme been independently reviewed in the past 12 to 18 months?

Third, Travel Rule operational compliance. Can the VASP demonstrate, with screenshots or system logs, how it collects, transmits and receives Travel Rule data? Has it implemented a recognised VASP-to-VASP messaging protocol?

Fourth, beneficial ownership clarity. Is the full UBO chain documented, verified and presentable to an institution applying EU AML standards? Are there any intermediate holding entities in jurisdictions that EU institutions treat as high-risk or non-cooperative?

Fifth, transaction-profile documentation. Does the VASP have a clear, written account of its anticipated transaction volumes, customer segments, geographies and product types? Can it explain how it handles high-risk customers and what its exposure to sanctioned jurisdictions is?

Operators we advise routinely discover, at this stage, that one or two of these factors require remediation before an EMI approach is viable. That is the expected outcome of a readiness review – and far less costly than a failed onboarding.

If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Write to info@oboluslaw.com for a confidential review.

A common assumption: a single offshore licence is enough

A common assumption among inbound operators is that a single offshore VASP registration – in the BVI, Cayman Islands or a similar jurisdiction – provides a sufficient regulatory basis to onboard with any EMI and serve clients globally. This is consistently wrong in the Czech and EU context, and acting on it is one of the more expensive mistakes a VASP can make.

EU-licensed EMIs, including those passporting into the Czech Republic, apply EU AML standards to their customers regardless of where those customers are incorporated. An offshore VASP registration does not satisfy the ČNB's or the Bank of Lithuania's expectations for a CASP serving EU clients. It does not exempt the VASP from the Travel Rule. It does not address the financial-promotion rules that apply when the VASP markets to EU residents under MiCA.

More practically: EU correspondent banks have, over recent years, applied increasing scrutiny to EMIs that onboard offshore-registered entities with EU-facing operations. The result is that EMIs have themselves become more selective about which offshore-registered VASPs they will take on – and the threshold for EU-facing businesses has risen. The path of least resistance, for a VASP planning to operate substantively in the Czech Republic or the EU, is a MiCA CASP authorisation in a member state of choice, with the Czech Republic or another well-regarded hub as the licensing home.

We have seen operators delay this step for cost reasons, only to face de-risking events that cost more to resolve than the original licensing work would have. Operating without the right licence risks enforcement, frozen rails and lost banking – not as a hypothetical outcome, but as a documented pattern across the EU market.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks and EMIs close crypto company accounts primarily because the VASP's compliance posture – its AML programme, Travel Rule implementation, beneficial ownership documentation or transaction-flow controls – does not satisfy the institution's own regulatory obligations under applicable AML directives. De-risking also occurs when a correspondent bank pressures the EMI to exit high-risk categories. The closure is rarely arbitrary: it reflects a compliance judgment the institution has made under regulatory supervision. In most cases, the root cause is a gap in the VASP's documentation or a transaction-profile anomaly that the institution cannot adequately explain to its own regulator.

How can a VASP onboard with an EMI?

A VASP onboards with an EMI by presenting a complete compliance package covering its licensing status or application, its AML/CFT programme, its Travel Rule operational framework, its UBO structure and its anticipated transaction profile. The process is sequential: the EMI conducts a preliminary review, requests additional documentation, verifies beneficial ownership and then takes an internal compliance decision. Timelines vary considerably depending on the EMI's risk appetite and the completeness of the VASP's submission. A well-prepared submission – with all material gaps addressed before the formal approach – produces a materially faster result than an iterative, reactive process.

What does client-money safeguarding require?

Client-money safeguarding under EU payment-services rules requires a payment institution or EMI to hold funds received from customers in a segregated account at a credit institution, or to cover those funds with an appropriate insurance or guarantee, so that client money is protected in the event of the institution's insolvency. For a VASP using an EMI to hold client fiat balances, the key practical question is whether the safeguarding arrangement covers the specific account structure the VASP intends to use – including sub-accounts, pooled arrangements and any overnight sweep. Regulators, including the ČNB, expect the VASP to understand and document the safeguarding chain, not merely to hold the account.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams – mapping the licence, payment and custody stack before our clients commit capital. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP licensing transitions and EMI onboarding structuring across Central European and EU jurisdictions.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours