El Salvador's legal regime for digital assets is among the most explicit in the Western Hemisphere, yet the businesses that set up there routinely discover that legal clarity at home does not translate into open banking relationships abroad. A licensed Bitcoin Service Provider (a business holding a licence under El Salvador's Bitcoin Law and its successor regulatory framework) can find its correspondent accounts restricted, its EMI relationships terminated and its fiat rails severed — not because of anything it did wrong in El Salvador, but because a counterparty institution in a stricter jurisdiction applied its own de-risking calculus. That gap, between domestic legitimacy and cross-border banking access, is the live commercial problem for most digital-asset operators in El Salvador today.
This page sets out how account-closure defence works in El Salvador's regulatory context, how the cross-border interaction between El Salvador's Bitcoin Law regime, MiCA in the EU and the UK's FCA money-laundering registration framework affects banking access, and what a business can do — before and after an account is closed — to protect its fiat infrastructure.
El Salvador's digital-asset regime and the regulated basis for banking
El Salvador made Bitcoin legal tender under the Bitcoin Law, creating a framework in which digital-asset service activity is legally recognized at the national level. The country's financial regulator, the Comisión Nacional de Activos Digitales (CNAD, the National Commission of Digital Assets), supervises entities operating as Bitcoin Service Providers and, under the subsequent Digital Assets Issuance Law, issuers of tokenized instruments. Holding a CNAD licence is the starting point for any account-closure defence: without it, a business has no regulatory standing on which to anchor its argument to a correspondent bank or EMI.
The CNAD framework imposes AML/CFT obligations consistent with the FATF Recommendations (the Financial Action Task Force's global anti-money-laundering standards), including the Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer). This matters for account defence: a bank that closes an account citing AML risk can be engaged directly on whether the operator's Travel Rule compliance programme meets FATF standards. A well-documented compliance programme is the first tool in the defence.
In our practice, operators that arrive in El Salvador without a properly scoped compliance manual, a transaction monitoring policy and documented Travel Rule procedures are in the weakest position when a banking relationship is reviewed. The licence alone does not carry the argument.
What de-risking means in practice, and why El Salvador businesses are affected
De-risking is the practice by which a bank or electronic money institution (EMI) terminates or restricts a business relationship on the basis of perceived risk category rather than a specific finding of misconduct. For digital-asset businesses, the result is account closure, refusal of onboarding or the withdrawal of correspondent banking access — often with minimal notice and a generic explanation.
El Salvador businesses face a specific version of this problem. The country is small, its financial system has limited correspondent depth, and the novelty of the Bitcoin Law has made some overseas institutions cautious. A business with a Salvadoran operating entity frequently needs banking in a second jurisdiction — typically the EU, the UK, the US or a Caribbean financial centre — to reach the payment rails its clients actually use. Each of those jurisdictions applies its own standards to the Salvadoran entity's licence type, AML posture and ownership structure.
The practical consequence: an operator can be fully compliant in El Salvador and still face de-risking by a Lithuanian EMI, a UK-registered payment institution or a Cayman correspondent bank. The defence requires engaging the counterparty's regulatory regime, not just the home regime.
For a scoped assessment of your banking exposure, the first step is mapping which jurisdictions your payment flows touch and which regulators therefore have a view. The process above describes the standard path. Your facts — the entity structure, the user base and the banking stack — change the analysis. Map your options.
Why accounts close: the three patterns we see most often
Account closures in the El Salvador context cluster around three identifiable patterns, each with a different defence strategy.
The first is category-level de-risking: the bank has a blanket policy against crypto clients, regardless of compliance quality. Here the practical answer is an immediate application to a specialist EMI that has built crypto-client onboarding into its licence scope, while pursuing a formal complaint against the closing bank in the applicable jurisdiction if there is a statutory right to basic payment services.
The second is compliance-triggered closure: the bank flagged a specific transaction pattern, a beneficial owner disclosure gap or a Travel Rule failure. This is addressable. The business can produce an audit report, a remediated compliance manual and evidence of Travel Rule implementation to open a dialogue — but it needs to move quickly, because the closure notice typically starts a short clock for the business to move its balance.
The third is jurisdiction-triggered closure: the bank's correspondent has restricted exposure to entities domiciled in El Salvador, or the bank's own risk appetite has shifted after a regulatory review. This is the hardest to address at the relationship level. The structural response is a dual-entity structure — a licensed EU CASP (a Crypto-Asset Service Provider authorised under MiCA) or a UK-registered entity alongside the Salvadoran entity — so that the fiat-side operations run through an entity the banking counterparty recognizes without requiring a jurisdiction waiver.
How a VASP onboards with an EMI: the practical process
Onboarding a VASP (virtual asset service provider) with a specialist EMI is a structured due-diligence process that typically runs across several weeks and requires documentary preparation well in advance. An EMI onboarding an El Salvador-licensed entity will assess the CNAD licence scope, the AML/CFT framework in place, the beneficial ownership chain, the transaction volume profile, and the strength of the Travel Rule programme.
The core documentation set includes: the CNAD licence certificate and its scope annexures; the business's AML policy, CDD (customer due diligence) procedures and transaction monitoring configuration; the Travel Rule solution in use; a description of the expected transaction flows (volume, corridors, average ticket); and a personal disclosure pack for each beneficial owner above the threshold applied by the EMI.
In practice, the EMI will also want to understand the cross-border picture. If the Salvadoran entity is routing transactions to or from EU counterparties, the EMI will want to know whether the EU leg is handled by a MiCA-authorised CASP or whether the Salvadoran entity is providing services into EU clients directly — a fact that can trigger MiCA's territorial reach even for a non-EU domicile. We advise clients to map this exposure before they begin the EMI application, not after the EMI's compliance team raises it.
A common mistake at this stage: submitting a generic AML policy rather than a policy scoped to the entity's actual product, client base and transaction types. EMI compliance teams read these documents carefully. A mismatch between the policy and the described business is one of the most common causes of onboarding refusal.
The cross-border interaction: banking, tax and structure
El Salvador has no capital gains tax on Bitcoin profits for individuals and a favourable treatment for digital-asset businesses, which is part of its attractiveness for inbound operators. But tax treatment in El Salvador does not determine tax treatment in the jurisdictions where the business's clients sit, where its employees are, or where its banking counterparties are located.
A business that structures its operating entity in El Salvador while serving EU retail clients runs directly into MiCA's scope: providing crypto-asset services to persons in the EU from a third-country entity triggers MiCA's reverse-solicitation analysis. If the service is actively marketed into the EU rather than initiated by the client, the operator needs a MiCA CASP authorisation in a member state, not a workaround. The failure to address this is the single most common structural error we see in El Salvador-domiciled businesses with European user bases.
On the banking side, the dual-entity structure that addresses jurisdiction-triggered closure — a CNAD-licensed Salvadoran entity for domestic and Latin American operations, and a licensed EU or UK entity for European fiat flows — also has transfer-pricing implications. Intercompany flows between related entities in different tax regimes require a documented pricing policy. This is not optional once the structure reaches material transaction volumes.
Operators we advise routinely underestimate the cost and lead time of establishing banking for the EU entity. FCA-registered firms in the UK, and MiCA-authorised CASPs in the EU, still face prolonged onboarding queues at tier-one banks. A realistic operational timeline allows for parallel banking applications across multiple institutions rather than sequentially.
A recent account-defence matter
In a recent engagement, a Central American payments company holding a CNAD licence received a closure notice from a European EMI citing "elevated risk profile" associated with its jurisdiction of incorporation. The business had clean transaction history and a functioning Travel Rule solution, but its AML policy had not been updated since the CNAD authorisation and did not reflect the EMI's expectations under the FCA framework applicable to its UK-registered counterparty. We conducted a gap analysis, produced an updated compliance manual aligned to FATF Recommendation 15 and the applicable EMI's onboarding standards, and prepared a formal response letter setting out the regulatory basis for the client's compliance posture. The account was retained. The matter resolved within a matter of weeks, and the client subsequently established a secondary EMI relationship as a resilience measure.
Decision matrix: which structure fits which operator profile
Not every El Salvador-based digital-asset business faces the same de-risking exposure. The right structural response depends on the operator's activity, client base and ambition.
Profile A — El Salvador-only operator (local exchange, domestic wallet, remittance corridor to and from El Salvador): the primary instrument is the CNAD Bitcoin Service Provider licence, supported by a strong AML/CFT programme and a FATF-aligned Travel Rule solution. Banking risk is contained to Salvadoran and Central American correspondents. The key risk is thin correspondent depth; the mitigation is relationship diversity across domestic institutions.
Profile B — Latin American operator using El Salvador as a hub (serving multiple jurisdictions in the region through a Salvadoran entity): the CNAD licence is necessary but not sufficient. Each additional jurisdiction requires analysis of whether the cross-border service triggers a local VASP or payment licence requirement. Banking should run through a combination of a Salvadoran account and a Caribbean or US correspondent where available. The key risk is regulatory fragmentation across the regional client base.
Profile C — El Salvador entity with EU or UK user base: the CNAD licence does not address MiCA or FCA exposure. A parallel MiCA CASP authorisation in a passportable EU member state — or FCA registration in the UK — is operationally necessary. The fiat rails for EU flows should run through the EU entity to keep the banking relationship within the regulatory perimeter the EMI recognizes. This is the most complex profile and the one where early legal structuring saves the most time and cost later.
Profile D — Tokenized asset issuer under El Salvador's Digital Assets Issuance Law: issuing tokenized instruments from El Salvador requires CNAD authorisation under the issuance framework. Distribution to investors in other jurisdictions triggers securities analysis in each target market. Banking for the issuance proceeds typically requires a licensed entity or an institutional custodian in the investor's home jurisdiction. This profile should engage counsel before marketing commences.
If a prior application stalled, an account was closed, or your structure no longer fits your business, a second read of the facts can surface the structural reason and the route forward. Map your options.
Self-assessment: is your banking defensible today
The following questions are the ones a specialist EMI compliance team or a de-risking bank will ask. If the answer to any of them is unclear, the account relationship is at risk.
- Does the business hold a current, in-scope CNAD licence that covers all of its actual activities?
- Is the AML policy scoped to the entity's specific product, client profile and transaction corridors — and updated within the last twelve months?
- Is a Travel Rule solution in production, with documented procedures for both inbound and outbound transfers?
- Is the beneficial ownership chain fully documented, with certified copies available on short notice?
- Has the business mapped which jurisdictions its users are in, and confirmed that it either holds a local licence or has a defensible reverse-solicitation analysis for each material user jurisdiction?
- Does the business maintain a secondary banking or EMI relationship so that a single closure does not interrupt operations?
- Is there a documented policy for responding to a banking relationship review, including a designated point of contact and a document production timeline?
We map the licence stack across operating, custody and payment layers before a client commits to a structure, precisely because the answers to these questions determine whether banking is achievable — and on what timeline.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for digital-asset businesses – structuring fiat rails, EMI onboarding and payment licence strategy across jurisdictions
- Payment institution licensing in the European Union under MiCA – MiCA CASP authorisation, passporting and the EU fiat-rail architecture
- Real-world asset tokenization in Guernsey – tokenized instrument structuring and regulatory treatment in a leading offshore centre
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily through de-risking: a judgment that the category of client presents a disproportionate compliance burden relative to revenue, regardless of individual conduct. Specific triggers include inadequate AML documentation, undisclosed beneficial owners, Travel Rule non-compliance, jurisdiction-level risk policies or a correspondent bank's own restrictions. In El Salvador, the novelty of the Bitcoin Law regime can itself be a trigger with overseas counterparties that have not assessed the CNAD framework. A strong compliance file and a documented regulatory standing are the primary defence.
How can a VASP onboard with an EMI?
A VASP onboarding with a specialist EMI must demonstrate: a valid operating licence in its home jurisdiction; an AML policy scoped to its actual activities; a functioning Travel Rule solution; a clean beneficial ownership chain with certified documentation; and a credible transaction volume and corridor profile. The EMI will also assess whether the VASP's cross-border activities trigger licensing obligations in the EMI's own jurisdiction. Preparation of a complete due-diligence pack before the application — rather than responding reactively to information requests — materially shortens the onboarding process.
What does client-money safeguarding require?
Client-money safeguarding requirements vary by jurisdiction but generally require that funds received from clients are held separately from the firm's own funds, in an account designated for the purpose at an authorised institution, and are not co-mingled with operational capital. Under the FATF framework and most licensed VASP regimes — including those referenced in MiCA and the FCA's applicable rules — safeguarding also requires documented procedures, reconciliation and, in some regimes, insurance or guarantee arrangements. Operators that receive fiat from clients before conversion to digital assets typically need a payment institution or EMI licence to hold those funds lawfully.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. Operators we advise receive a licence-stack map across operating, custody and payment layers before committing to a structure — because the banking is always part of the legal problem. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst — specialising in VASP licensing, AML frameworks and the cross-border banking interaction for digital-asset businesses operating across multiple jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.