EST · MMXXVI
Home/Jurisdictions/Eu Mica/Fiat on/off-ramp banking in European Union (MiCA)
Banking, Payments & EMI Onboarding

Fiat on/off-ramp banking in European Union (MiCA)

Fiat on/off-ramp banking in European Union (MiCA). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

A crypto exchange that has cleared MiCA CASP authorisation still lacks one critical component: a bank account that accepts and releases euros on behalf of clients. Without reliable fiat on/off-ramp access – the infrastructure that converts client euros into digital assets and back again – the licence is commercially inert. That is the defining operational risk for EU-based digital-asset businesses right now, and it is the question this page answers directly.

Under the MiCA regime, operated by ESMA and the relevant national competent authorities, a CASP (crypto-asset service provider) authorisation governs the digital-asset activity. It does not, by itself, compel any bank or EMI (electronic money institution) to open an account. The practical result is that CASP authorisation and banking access are parallel problems requiring parallel legal strategies.

This page covers the regulated basis for fiat rails inside the EU, the onboarding process with banks and EMIs, the cross-border interaction with payment licensing and tax structure, and the decision point at which operators must choose their banking architecture before committing capital to the MiCA application.

Why Fiat Rails Are a Regulated Problem, Not Just an Operations Problem

The failure to secure fiat rails is not a banking relationship issue. It is a regulatory classification problem. A CASP that holds client funds pending conversion is engaging in conduct that sits at the intersection of two distinct EU regimes: MiCA, supervised by ESMA and the national competent authorities, and the payment services and e-money frameworks that govern the movement of euros.

Where a CASP handles client euro deposits – receiving fiat, holding it briefly, and releasing it after settlement – the activity may also qualify as payment services or e-money issuance under EU law. Operators that do not hold the appropriate payment or e-money licence cannot legally perform those activities themselves. They must therefore rely on a regulated EMI or payment institution as the fiat layer beneath the CASP stack. That dependency is structural, not incidental.

Regulators across the EU increasingly scrutinise how CASPs manage the boundary between their own authorised perimeter and the payment layer. Operators we advise routinely discover, after CASP authorisation, that their proposed banking partner interprets the MiCA licence narrowly and will not provide settlement accounts without additional assurances on AML controls, beneficial ownership and projected transaction volumes. The licence alone is not the answer.

ESMA and national competent authorities have issued guidance on the safeguarding obligations that apply to client funds held by CASPs pending execution. Understanding exactly which regulated perimeter covers which fund flow is the starting point for any banking conversation.

The CASP/EMI Architecture: How the Two Layers Interact

The standard fiat on/off-ramp architecture for a MiCA-authorised CASP is a two-layer structure: the CASP holds and settles the digital-asset side; an EMI or payment institution holds and moves the euro side. The two entities are connected by an API and a contractual agreement that allocates regulatory responsibility for each transaction segment.

The EMI must itself be authorised under the applicable EU payment services regime and must conduct its own Travel Rule (the obligation to pass originator and beneficiary data with a transfer) and AML due diligence on the CASP as a business client. That means the CASP must present its own compliance programme – its KYC controls, its transaction monitoring, its suspicious-activity reporting procedure – to the EMI as part of the onboarding process. The EMI is not simply a service provider; it is a gatekeeper with its own regulatory exposure.

In our practice, we have seen two recurring failure modes at this interface. First, CASPs that approach EMI onboarding without a structured compliance dossier are rejected or placed in indefinite review. Second, CASPs that use an EMI domiciled outside the jurisdiction of their CASP authorisation create a cross-border mismatch that raises questions from both the national competent authority and the EMI's home regulator. Both failure modes are avoidable with early structuring.

For operators whose projected volumes exceed what a standard EMI can process, the alternative architecture is to obtain a payment institution licence alongside the CASP authorisation, or to acquire or white-label an existing licensed payment business. Each route has a different regulatory timeline and capital implication that must be assessed before the CASP application is filed.

The process above describes the standard path. Your facts – the entity, the user base, the transaction mix – change the analysis. For a scoped assessment of your banking architecture under MiCA, contact OBOLUS at Map your options.

Which CASP Activities Generate Fiat Exposure?

Not every MiCA-authorised activity creates the same fiat banking risk. The exposure level depends directly on which CASP activities are included in the authorisation scope.

Exchange services – the conversion of one crypto-asset for fiat currency or vice versa – generate the most direct and sustained fiat exposure. The CASP is the counterparty to client fiat legs, which means euro balances appear in the flow of funds continuously. This activity cannot be operated without a robust fiat settlement account and, in most practical architectures, without an EMI partnership or an in-house payment licence.

Custody and administration services generate lower but non-trivial fiat exposure. Clients will deposit and withdraw in fiat even if the CASP's core function is safeguarding the digital asset. The custody CASP must ensure the fiat receipt and release function is covered by a regulated entity in the chain.

Advisory and portfolio management services typically generate episodic rather than continuous fiat flows. The banking burden is lower, but the CASP still requires a business bank account with SEPA access, which remains difficult to secure for digital-asset businesses in several EU member states.

Transfer and execution services sit between exchange and advisory in terms of fiat exposure. The relevant question is whether the CASP touches client fiat at all or merely transmits instructions. Where the CASP does hold fiat, even briefly, it sits inside the safeguarding perimeter established under the applicable MiCA provisions.

How Do EU Banks Assess a CASP Client?

EU-regulated banks assess CASP clients through the same AML/CFT lens they apply to any financial institution client – but with a higher baseline level of scrutiny driven by the perceived risk category of digital-asset businesses.

The bank's due-diligence process typically examines the CASP's authorisation status, its beneficial ownership structure, its jurisdiction of incorporation, its AML policy and control framework, its projected transaction volumes and corridors, and its source-of-funds evidence for initial capital deposits. In several major EU banking markets, internal de-risking policies at large commercial banks mean that CASP clients are referred to specialist teams or declined at the preliminary screening stage, regardless of their licence status.

The operators most likely to succeed in EU bank onboarding share three characteristics: they hold or are actively processing a CASP authorisation from a recognised national competent authority; their corporate structure is clean, with no multiple-layer offshore holding companies between the CASP entity and its ultimate beneficial owners; and their AML documentation is already at the standard the bank would expect of a regulated financial institution, not a startup.

A CASP domiciled in a member state with a well-regarded national competent authority – the Bank of Lithuania under the MiCA transition, the MFSA in Malta, or a larger-market NCA such as BaFin or the AMF – carries more weight in a bank's risk committee than a CASP operating on a third-country registration. That reputational weighting is a structuring consideration, not a post-authorisation afterthought.

The EMEA Cross-Border Fiat Complication: Where the Entity Sits vs. Where Users Are

The cross-border dimension of fiat on/off-ramp banking is the most underestimated risk in MiCA structuring. A CASP authorised in one member state can passport its digital-asset services across the EU. It cannot passport its bank account or EMI relationship on the same terms.

An operator whose CASP is licensed in Lithuania, whose banking is with an EMI headquartered in Malta, and whose primary user base is in Germany and France faces three distinct regulatory supervisions simultaneously: the Bank of Lithuania for the CASP authorisation, the MFSA for the EMI's home-state supervision, and the BaFin and AMF for consumer-facing marketing and local AML requirements. Each supervisor may request information, and their expectations may not be fully aligned.

The Travel Rule obligation compounds this. When a CASP processes a fiat-in transaction from a German client, the corresponding crypto transfer – once it occurs – triggers Travel Rule data obligations under the applicable EU provisions. That data must flow between the CASP and the counterparty VASP, and the fiat leg must be reconciled to the crypto leg in the transaction monitoring system. An EMI that is not configured to receive and store Travel Rule data creates a compliance gap that both the NCA and the EMI's own supervisor may flag.

In our cross-border practice, we have structured operations for CASPs that serve users across multiple EU member states from a single authorisation, using a combination of EMI partnership agreements, intra-group payment service arrangements and localised AML monitoring overlays. The structure requires documented legal analysis in each market, not a generic assumption that passporting solves the problem.

A recent matter illustrates the point. In late 2024, a digital-asset exchange that had received CASP authorisation in an EU member state approached us after its primary EMI relationship was terminated without notice, citing revised internal risk appetite. The exchange had no secondary banking arrangement and faced an operational standstill. We identified a compliant EMI in a different member state, structured the transition to avoid a regulatory notification gap, and mapped the Travel Rule data requirements against the new EMI's capabilities. The exchange resumed full fiat operations within a matter of weeks. The underlying cause was a single point of failure in the fiat architecture – a structural risk that pre-authorisation planning would have eliminated.

If a prior application stalled, a banking relationship was closed, or your fiat rails are at risk, a second read can surface the structural reason and the route back. Reach our banking desk at Map your options.

Safeguarding Client Money Under MiCA: What the Regime Requires

MiCA establishes explicit safeguarding obligations for CASPs that hold client funds or crypto-assets. For fiat-denominated client balances, the requirement is that funds are held in a segregated account at a credit institution or, where permitted, in a qualifying money-market fund – separate from the CASP's own working capital at all times.

The segregation obligation is not merely an accounting requirement. It determines which banking relationships are legally adequate. A CASP that holds client euros in a pooled omnibus account at a bank that does not acknowledge the trust character of the funds has not satisfied the safeguarding requirement, regardless of internal accounting entries. The bank must accept the account on terms that recognise client ownership of the balance.

That requirement has practical implications for EMI selection. Not every EMI operating in the EU is set up to offer segregated client accounts on terms that satisfy the MiCA safeguarding conditions. The CASP's legal counsel must review the EMI's account terms, the applicable national implementation of the safeguarding rules, and the interaction between the EMI's own regulatory obligations and those of the CASP before the architecture is finalised.

For custodian CASPs, there is a parallel obligation on the crypto-asset side. Client assets must be segregated from proprietary holdings, with records maintained that allow immediate identification of each client's entitlement. The fiat and crypto segregation obligations together define the minimum viable compliance infrastructure for any CASP operating a mixed fiat/crypto book.

Self-Assessment: Before You Engage a Bank or EMI

The following checklist reflects the assessment we run for clients before any bank or EMI outreach. Each point represents a common gap that, left unaddressed, produces a rejection or an extended due-diligence delay.

  • CASP authorisation status: is the authorisation granted, in process, or pending a completeness assessment by the NCA? Banks will not open accounts for unlicensed applicants in most EU markets.
  • Corporate structure: is the beneficial ownership chain short, documented, and consistent across all regulatory filings? Discrepancies between the CASP application and the banking application are the most common rejection trigger.
  • AML/KYC documentation: is the compliance programme written at the standard of a regulated financial institution, with named MLRO, tested procedures and a current risk assessment?
  • Transaction profile: is there a documented business plan with projected volumes, average transaction sizes, geographic user distribution, and source-of-funds rationale for initial capital?
  • Safeguarding analysis: has counsel confirmed that the proposed bank or EMI account structure meets the MiCA safeguarding conditions in the relevant member state?
  • Travel Rule readiness: is the CASP's transaction monitoring system capable of producing and receiving Travel Rule data packets, and has the EMI confirmed its own Travel Rule integration?
  • Secondary banking contingency: is there a documented fallback EMI or payment institution in the event the primary relationship is terminated?

Operators that can answer all seven points clearly before approaching a bank or EMI close in materially shorter timelines than those that treat the banking process as a post-authorisation administrative step.

Related at OBOLUS

A Common Assumption Worth Examining

A common assumption among operators entering the EU market is that a single offshore licence – from the BVI, Cayman, or another offshore centre – is sufficient to serve EU clients, accept their euros, and maintain a bank account in Europe. That assumption is incorrect on each of its three premises.

Serving EU clients with digital-asset services that fall within the MiCA perimeter requires MiCA authorisation, full stop. The offshore registration does not provide a passportable EU authorisation, does not satisfy the EU AML regime's requirements for entities dealing with EU residents, and does not give the operator a credible basis for approaching EU-regulated banks or EMIs. Those banks conduct their own regulatory assessment of the operator's licence status relative to EU law; an offshore registration that is not recognised under MiCA will not clear that assessment.

The offshore structure may remain relevant for specific purposes: holding company domicile, treasury management, investment fund structuring, or serving non-EU users. But the fiat on/off-ramp for EU users requires an EU-regulated entity – a CASP authorised under MiCA and a payment or e-money layer compliant with the applicable EU payment services regime. Operators that attempt to maintain EU fiat rails through an offshore entity risk enforcement action from the relevant NCA and account closure by the bank once the mismatch is identified.

We map the full licence stack – operating entity, custody layer, payment layer – before a client commits capital to any structure. That mapping prevents the most expensive mistake in EU digital-asset structuring: building a business on a regulatory foundation that does not match the actual activity.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses – never for retail clients. Operators we advise routinely present their banking and EMI applications with counsel-reviewed compliance dossiers, materially improving onboarding outcomes. To discuss your MiCA fiat infrastructure, contact info@oboluslaw.com or message us at t.me/oboluslaw.

To map the licence, banking and payment layer for your EU build, write to OBOLUS. Map your options.

FAQ

Why do banks close crypto company accounts?

EU-regulated banks close crypto company accounts primarily because of internal de-risking policies, AML exposure concerns, and the perceived complexity of monitoring digital-asset transaction flows. A CASP that presents inadequate AML documentation, an opaque beneficial ownership structure, or unexplained transaction patterns gives the bank's compliance function grounds to terminate the relationship. Proactive disclosure of the CASP authorisation status, a structured compliance dossier, and clear transaction profiling materially reduce the risk of closure.

How can a VASP onboard with an EMI?

A VASP – or, under MiCA, a CASP – onboards with an EMI by presenting itself as a regulated financial institution client, not a startup. The EMI will conduct full AML due diligence on the CASP: corporate structure, beneficial ownership, authorisation documentation, AML programme, projected volumes, and transaction corridors. Operators who arrive with a counsel-reviewed compliance dossier, Travel Rule-ready systems, and a documented business plan close the EMI onboarding process significantly faster than those who approach it as an administrative formality.

What does client-money safeguarding require?

Under MiCA, a CASP holding client fiat funds must keep those funds segregated from its own working capital in an account at a regulated credit institution or qualifying money-market fund. The bank or EMI must accept the account on terms that recognise the client-owned character of the balance. An omnibus account without the appropriate trust acknowledgment does not satisfy the safeguarding requirement. Counsel should review the EMI's account terms and the national implementation of the MiCA safeguarding provisions before the architecture is finalised.

By Victor Olsen, Regulatory & Compliance Analyst – specialist in MiCA CASP authorisation, AML/Travel Rule compliance, and banking access strategy for EU-regulated digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours