Estonian crypto businesses losing banking access face a compounding crisis: without fiat rails (the bank accounts and payment channels that connect a crypto operation to the conventional financial system), a licence becomes a liability rather than an asset. De-risking – the practice by which banks and payment institutions exit relationships with higher-risk clients, including virtual asset service providers – has closed or frozen accounts across the Estonian market as global correspondent banking pressure tightened. The applicable legal regime is anchored in Estonia's Money Laundering and Terrorist Financing Prevention Act and the transitioning Virtual Currency Service Provider (VCSP) framework, now converging toward the MiCA (Markets in Crypto-Assets Regulation) CASP authorisation model supervised at the EU level by ESMA and national competent authorities. This page maps the de-risking risk, the defence options available to a VCSP or incoming operator, and the cross-border decisions that determine whether fiat access can be restored or preserved.
What de-risking means for an Estonian VCSP
De-risking, in the Estonian banking context, is a creditor's unilateral exit from a business relationship it judges to carry regulatory, reputational or correspondent-banking risk that exceeds the commercial return. Banks rarely publicise the decision criteria. In our cross-border practice, we see the trigger most frequently in three patterns: a correspondent bank's blanket policy against crypto-counterparty exposure; a domestic bank's own AML risk appetite review; and a regulator-driven supervisory letter signalling heightened scrutiny of an account category. For an Estonian VCSP, any of these can mean an account closure notice with contractual notice periods that may run to as little as a few weeks.
Estonia's Financial Intelligence Unit (FIU) has been the primary licensing authority for VCSPs since the original 2017 regime, and the FIU's own enforcement activity – including its large-scale licence revocations in 2022 – reshaped local bank risk appetite significantly. Institutions that previously onboarded VCSPs without deep due diligence began treating the category as uniformly elevated-risk regardless of individual compliance posture. The result: a legitimate, well-structured VCSP with a valid FIU authorisation may still face de-risking simply because of sector association.
The cross-border dimension sharpens the problem. An Estonian entity may hold an FIU authorisation and serve users across the EU under pre-MiCA passporting assumptions, while its payment accounts sit with a Latvian or Lithuanian EMI and its correspondent layer runs through a German or Dutch bank. Each institution in that chain applies its own de-risking threshold. A closure at any node disrupts the full fiat stack.
What is the legal basis for challenging an account closure?
A VCSP that receives a closure notice is not without legal recourse, but the recourse is procedural and contractual rather than a right to maintain the account indefinitely. Estonian law, consistent with EU payment services directives, generally permits payment service providers to terminate a framework contract on notice, subject to that notice meeting the contractual and statutory minimum. The defence posture therefore focuses on three lines: contesting procedural defects in the notice; demonstrating that the closure decision was based on a risk assessment that does not reflect the client's actual compliance standing; and, in parallel, accelerating the search for replacement infrastructure.
The FATF Recommendations, specifically the guidance on Recommendation 15 addressing virtual assets, explicitly caution against wholesale de-risking as a substitute for targeted risk management. A well-documented response letter referencing the FATF guidance, combined with a refreshed AML/KYC file, can slow a closure decision while the institution re-examines its risk scoring. We have seen this approach buy meaningful time in practice. It is not a guarantee of reversal, but it changes the negotiating dynamic.
Where a closure is alleged to breach a framework contract's termination provisions – for example, where a stated reason proves to be inconsistent with the bank's own documented risk policy – a contractual claim is available in Estonian courts or, where an EMI relationship is involved, potentially before the EMI's home-state regulator. The claim is typically for damages arising from the disorderly closure rather than for specific performance restoring the account. The realistic outcome in most contested closures is a managed exit rather than reinstatement.
For a scoped assessment of your de-risking exposure and the response options available under Estonian and EU law, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base, the correspondent chain – change the analysis materially.
How does MiCA change the de-risking equation?
MiCA's CASP authorisation model, supervised by ESMA and the relevant national competent authority, introduces a materially different compliance signal to the banking market. A CASP authorisation is a more demanding credential than the prior Estonian FIU VCSP registration: it carries explicit own-funds requirements, governance standards, custody and safeguarding obligations, and a whitepaper regime for token offerings. Banks with global correspondent relationships increasingly distinguish between pre-MiCA registered VCSPs and full CASP-authorised entities.
For an Estonian business, the transition path matters. An entity that proactively pursued CASP authorisation – rather than waiting for the transitional deadline – arrives at its banking conversations carrying demonstrably stronger regulatory standing. The argument to a correspondent-bank compliance team shifts from "we hold a light-touch FIU registration" to "we are authorised under the EU's primary virtual-asset regulation and subject to ongoing ESMA and national supervisor oversight." That is a different conversation, and in our experience it produces different results at the onboarding stage.
MiCA also introduces explicit rules for asset-referenced tokens (ARTs) and e-money tokens (EMTs), imposing reserve and redemption requirements that parallel banking-grade obligations. An Estonian entity issuing or dealing in these instrument classes faces a dual regulatory conversation: the CASP licence and the token-specific regime. Collapsing those into a single, well-presented compliance narrative before approaching an EMI or bank is the practical starting point.
What does EMI onboarding require for a crypto business?
EMI onboarding (the process of establishing an account relationship with an electronic money institution licensed under the EU's Electronic Money Directive or its successor regime) has become the primary fiat-access route for Estonian crypto businesses that cannot sustain a full commercial bank relationship. EMIs operate under a lighter-touch capital base than banks, but they are not risk-neutral: every EU-licensed EMI is itself subject to AML supervision and will apply its own customer risk scoring to a VCSP applicant.
The onboarding file a crypto business should bring to an EMI due diligence process is more extensive than a standard corporate account opening. At minimum it should include: the current FIU or MiCA CASP authorisation document; a detailed business model description identifying the user geographies, transaction types and average ticket size; an AML/CFT policy that maps to FATF Recommendation 15; a Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer) compliance framework; and source-of-funds documentation for the initial deposit base. Some EMIs now require a third-party AML audit or an opinion from external counsel. We regularly assist businesses in assembling and presenting this file.
The cross-border dimension is significant. An EMI licensed in Lithuania, the Netherlands or Malta may be the institution of choice for an Estonian entity. Each institution applies its home-state AML regime on top of its own internal policy. An Estonian VCSP approaching a Lithuanian EMI is, in effect, navigating two national supervisory cultures simultaneously. Preparation for that dual-lens review is where most onboarding failures occur.
In a recent matter, a payments-adjacent digital-asset company with a valid Estonian FIU authorisation had seen three successive EMI applications rejected without substantive explanation. We reviewed the company's AML file, identified that the Travel Rule framework was drafted for peer-to-peer transfers and did not address the company's institutional settlement flows, and restructured the presentation. The subsequent EMI application was successful within a matter of weeks. The structural issue was not the business model – it was the compliance narrative presented to the EMI's risk team.
What does the cross-border licensing and banking stack look like for an Estonia-based operator?
An Estonian digital-asset business operating at scale typically sits across three legal and regulatory layers simultaneously, and a failure in any one of them can destabilize the others. Understanding that architecture is the starting point for any de-risking defence or banking-access strategy.
The operating layer is the FIU authorisation or, progressively, the MiCA CASP authorisation. This determines what the entity is permitted to do – exchange, custody, transfer, advisory. Under the MiCA transition, the continued validity of activity conducted under an FIU authorisation depends on the transition timetable the Estonian competent authority implements, and businesses that have not mapped that timeline face gap risk.
The payment layer is the EMI or bank account relationship. As discussed, this is the most fragile element for most Estonian VCSPs. An entity holding a valid CASP authorisation but no fiat account is commercially non-functional. The payment layer is also the one most susceptible to de-risking by third parties outside the entity's direct control.
The custody layer matters where the business holds client virtual assets. MiCA imposes explicit safeguarding and segregation expectations on CASP custodians. A business that comingles client assets – or whose custody process does not meet the MiCA standard – will fail the due diligence of any serious EMI or banking partner, because those institutions are themselves performing look-through assessments of the crypto business's client-asset risk. The custody posture therefore has a direct effect on banking access.
For an operator considering an Estonian domicile alongside a payment-friendly EU jurisdiction for the fiat account and a third jurisdiction for fund custody, the legal question turns on how those layers interact under AML, tax and regulatory reporting obligations. We map that stack as an integrated exercise, not as three separate retainers.
Which business profiles face the highest de-risking risk?
De-risking risk is not uniformly distributed across the Estonian VCSP population. Based on patterns in our cross-border practice, the profiles most exposed are those where the business model creates correspondent-bank risk at the clearing layer rather than only at the direct account layer.
A high-volume retail exchange processing large numbers of small transactions across multiple jurisdictions generates the AML-screening and transaction-monitoring load that correspondent banks find most difficult to manage. The risk is not necessarily that any individual transaction is suspicious – it is that the aggregate volume and geographic spread creates an exposure that the bank cannot cost-effectively supervise. These businesses face the steepest de-risking probability and require the most proactive banking strategy, including diversification across multiple EMI relationships before a closure event occurs.
A cross-border payments business using crypto rails for fiat-equivalent settlement sits at the intersection of the Payment Services Directive, the Travel Rule and the VASP AML regime. Every institution in the correspondent chain applies a different interpretation of how these obligations interact. Gaps in the business's own Travel Rule compliance are quickly surfaced during correspondent-bank audits and routinely trigger account reviews.
An institutional OTC desk or custody provider faces lower transaction-volume risk but higher single-counterparty concentration risk. A custody business whose client base is concentrated in one geography or one asset class will face targeted due diligence on those parameters. If the geography is one where FATF has identified AML/CFT deficiencies, the correspondent-bank response may be categorical rather than analytical.
A token issuer or DeFi-adjacent entity that does not hold a VASP or CASP authorisation but maintains fiat accounts for treasury management sits in the most ambiguous position. Many such entities assume that treasury accounts are outside the VCSP perimeter. They are often wrong. A bank that identifies crypto-related flows through a corporate account will apply its VCSP policy to the account regardless of the entity's own self-classification.
If your business has already received a closure notice or a risk-review letter, reach our banking access desk now at info@oboluslaw.com. If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back.
A common assumption that accelerates de-risking
A pervasive assumption among operators entering the Estonian market is that a single offshore licence – a BVI, Cayman or even a pre-MiCA FIU registration – is sufficient to serve a global client base from an Estonian entity. It is not. Each jurisdiction where a VCSP actively solicits, services or settles with users applies its own licensing analysis, and many of those analyses do not accept extraterritorial licensing equivalence.
The practical effect on banking is direct. An EMI or bank that performs a look-through assessment of a VCSP's user base and identifies that the business is servicing users in jurisdictions where it holds no local authorization will treat that as an AML red flag – not because the business is engaged in illegal activity, but because the regulatory gap creates an enforcement exposure that the bank cannot quantify. That unquantified exposure becomes a de-risking trigger.
The correct approach is to map the licence requirement at each layer of the business – operating, payment and custody – against the geographies actually served, and to close the gaps before approaching a banking partner. That mapping exercise is the foundation of the OBOLUS banking-access process. We deliver it as a scoped fixed-format assessment before the first EMI conversation begins.
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because of correspondent-bank pressure, internal AML risk-appetite reviews, and the cost of supervising high-volume or geographically dispersed transaction flows. A crypto business that cannot demonstrate a credible AML/CFT framework, Travel Rule compliance and a clear regulatory authorisation – such as a MiCA CASP or a valid FIU registration – presents a risk profile that many banks judge to exceed their risk tolerance, regardless of the individual business's actual compliance posture.
How can a VASP onboard with an EMI?
A VASP (virtual asset service provider) onboarding with an EMI should present a complete due diligence file covering its regulatory authorisation, a detailed business model description, an AML/CFT policy aligned to FATF Recommendation 15, a Travel Rule compliance framework, and source-of-funds documentation. EMIs apply their own risk scoring independently of the VASP's licensing status. A well-structured presentation that addresses the EMI's specific risk concerns – user geographies, transaction types, custody arrangements – materially improves onboarding success rates.
What does client-money safeguarding require?
Client-money safeguarding under EU payment services rules and MiCA requires that a CASP or EMI hold client funds in segregated accounts or, where applicable, in liquid low-risk assets, separate from the firm's own assets. The safeguarding method, the eligible custodian and the reconciliation frequency are all prescribed by the applicable regime. A business that commingles client and firm funds – or that cannot demonstrate real-time reconciliation – will fail the due diligence of banking partners and risk regulatory action from the competent authority.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital-Asset Businesses – the full practice area overview covering fiat-access strategy across jurisdictions
- De-risking and Account Closure Defence – Legal Counsel – the service page with process detail, scope options and engagement terms
- Fund Domicile Selection: the Compliance Burden in Practice – how domicile choice affects the tax, banking and regulatory stack simultaneously
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence stack across operating, custody and payment layers before you commit – not after an account closure forces the question. To discuss your situation, contact info@oboluslaw.com or message us via t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP licensing transitions and de-risking defence for digital-asset businesses in EU and cross-border contexts.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.