EST · MMXXVI
Home/Jurisdictions/Germany/Client funds safeguarding in Germany (BaFin)
Banking, Payments & EMI Onboarding

Client funds safeguarding in Germany (BaFin)

Client funds safeguarding in Germany (BaFin). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Client funds safeguarding in Germany is governed by the BaFin (Bundesanstalt für Finanzdienstleistungsaufsicht) regulatory regime, which requires any business holding client money in connection with payment or crypto-asset services to meet defined safeguarding obligations under German law. For a digital-asset company operating into or out of Germany – whether as an exchange, a custodian, or a payments intermediary – the failure to structure these obligations correctly exposes the business to enforcement, account closure, and potential criminal liability. This page maps the applicable regime, the inbound process, and the cross-border variables a general counsel needs to resolve before committing to a German-facing operational model.

What client funds safeguarding actually means under BaFin supervision

Client funds safeguarding in Germany means that money held on behalf of clients must be segregated, ring-fenced, and protected against insolvency of the service provider. BaFin supervises this obligation across two principal regimes: the payment services framework (implementing the EU Payment Services Directive) and the crypto-asset custody and services regime now transitioning under MiCA. A business that mixes client money with its own operational funds, or relies on an unregulated third-party account to hold fiat received from users, is in breach of both regimes and risks immediate supervisory intervention.

The core safeguarding obligation operates at three levels. First, the business must identify client money as a distinct legal category at the point of receipt. Second, it must place that money in a safeguarding account at a credit institution or in qualifying liquid assets separated from the firm's own estate. Third, it must maintain records sufficient to reconcile client balances at any time.

For crypto-asset businesses, the picture is more complex. Where a firm holds both fiat and crypto assets on behalf of clients, the fiat element triggers payment-services safeguarding rules while the crypto element falls under the custody provisions of the German crypto-asset services regime – now aligning to the MiCA CASP authorisation framework administered at EU level by ESMA, with BaFin as the national competent authority for German-incorporated entities. A business operating across both asset classes without separate analysis of each holding type is, in our experience, the most common structural error we see in inbound mandates.

CTA #1: The analysis above describes the standard path. Your facts – the entity structure, the user base, the nature of the assets held – change the analysis materially. Map your options with OBOLUS before you commit to a German operational model.

Who needs a German safeguarding structure?

Any business that receives, holds, or transmits fiat or digital assets on behalf of clients who are resident or domiciled in Germany will likely require a safeguarding structure compliant with BaFin's expectations – regardless of where the operating entity is incorporated. The jurisdictional reach of BaFin's supervisory authority is triggered by the location of the client, not only the location of the firm.

The most common profiles we advise are: an EU-incorporated VASP (virtual asset service provider) seeking to passport services into Germany under MiCA; a non-EU exchange or payment processor that has acquired a material German user base and needs to regularize its position; and a fintech or neo-bank holding an EMI (electronic money institution) licence in another EU member state that is now exploring whether its German activities require a local branch or enhanced safeguarding notification to BaFin.

The EMI passporting scenario deserves attention. Under the EU framework, an EMI authorised in one member state may provide services in Germany without a German licence, but it must notify BaFin and – critically – its safeguarding arrangements must still meet the standards the German supervisory environment expects. BaFin has a track record of scrutinizing inbound passported entities for the substance of their safeguarding arrangements, not merely their formal authorisation status.

Operators relying on the premise that a single offshore licence is sufficient to serve German clients globally are exposed. That assumption collapses the moment a German bank or payment processor reviews the counterparty's regulatory status and finds that the entity's safeguarding structure does not align with the expectations of the Payment Services Directive or MiCA as transposed in Germany.

What does the BaFin authorisation or registration process involve?

The process for obtaining BaFin authorisation for payment or crypto-asset services – including the associated safeguarding permissions – involves a formal application that BaFin processes in stages, with the timeline varying by licence category and the completeness of the submission. Figures for specific timelines and capital thresholds are subject to BaFin's current published guidance, which should be verified against the applicable regime at the time of application; we do not quote figures that change with regulatory updates.

At a structural level, the application requires: a legal entity incorporated in Germany or, for passporting entities, a formal notification package; a business plan describing the payment or crypto-asset activities, the client asset flows, and the safeguarding model; policies on AML/CFT, the Travel Rule (the FATF-derived obligation to pass originator and beneficiary data with a transfer), and internal controls; evidence of fit-and-proper management; and a safeguarding opinion or legal analysis confirming that the proposed arrangement satisfies the applicable regime.

BaFin will issue questions during review. Response time matters. A well-prepared submission that pre-empts the most common BaFin information requests – particularly around the identity of the safeguarding bank, the account structure, and the reconciliation methodology – materially reduces the back-and-forth. In our cross-border practice, we prepare submissions that address these questions before BaFin raises them, rather than treating the review as a reactive exercise.

For businesses transitioning from the prior German crypto-custody registration regime to the MiCA CASP authorisation framework, the transition process requires engagement with both BaFin and ESMA's coordination layer. Entities that registered under the earlier German crypto-asset framework do not receive automatic MiCA authorisation; they must comply with the MiCA transition provisions and submit for CASP authorisation within the timelines set by the applicable transitional arrangements.

How does the German safeguarding regime interact with cross-border tax and banking?

A German safeguarding structure does not exist in isolation. For most digital-asset businesses, the German regulatory position sits within a broader structure that includes an entity in another EU hub (Lithuania, Malta, or Ireland are common), a custody layer in a non-EU jurisdiction, and banking relationships that span multiple countries. Each layer interacts with the German safeguarding obligation in ways that can produce structural vulnerabilities if they are not designed together.

On the banking side, the safeguarding account itself must be held at a credit institution that accepts the business and is willing to designate the account as a client-funds safeguarding account. German banks and international banks with German branches have tightened their onboarding criteria for crypto-adjacent businesses significantly. A business that has not pre-qualified its banking counterparty before submitting to BaFin risks reaching authorisation without a functioning safeguarding arrangement – which is a supervisory gap BaFin treats seriously.

We regularly advise on the EMI onboarding process as a parallel track: in many cases, the fastest route to a functioning German-facing fiat rail is not a German licence but an EU-passported EMI that has successfully completed BaFin notification and maintains a safeguarding account with a German credit institution or a qualifying European counterpart. This requires co-ordination between the licensing analysis, the banking mandate, and the contractual terms of the EMI relationship.

On tax, the treatment of client funds held in a safeguarding account – and the income derived from those funds – interacts with German corporate tax and withholding rules in ways that depend on the entity structure. A German-incorporated operating company holding client funds will be assessed on interest or yield arising on those funds differently from a passporting EU entity. We map these interactions before the structure is committed, not after the first German tax filing arrives.

The cross-border reality also means that German AML requirements apply alongside the FATF Recommendation 15 baseline and MiCA's AML expectations. A VASP serving German clients must apply customer due diligence standards consistent with the EU AML framework, collect and transmit Travel Rule data at the applicable threshold, and maintain records accessible to BaFin on request. Allied counsel in the relevant jurisdiction can address local implementation specifics where the VASP's home-state rules diverge from the German transposition.

What are the most common safeguarding mistakes that trigger BaFin enforcement?

The most frequent safeguarding failures we see in German-market mandates fall into four categories, each of which can trigger BaFin enforcement action ranging from a supervisory letter to a formal prohibition order.

The first is commingling. Client money held in a general operating account – even temporarily, even with internal bookkeeping that tracks the split – does not satisfy the segregation requirement. BaFin looks at the legal character of the account, not the firm's internal accounting. A safeguarding account must be legally designated as such from the moment funds are received.

The second is reliance on an unregulated sub-custodian. Some businesses route client fiat through a third party that is not itself a regulated credit institution or qualifying asset manager. This arrangement fails the safeguarding test regardless of the commercial logic behind it.

The third is a mismatch between the regulatory perimeter and the actual business. A firm that obtained an older German crypto-custody registration but has since expanded into payment initiation, exchange, or lending has likely outgrown the scope of that registration and is operating unlicensed activities without realising it.

The fourth – and the one we see most often in inbound cross-border mandates – is the belief that a non-EU licence insulates the business from BaFin's reach. A business serving German clients from an offshore entity with no EU authorisation is offering regulated services in Germany without a licence. BaFin has consistently acted on this basis, and the consequences include public warnings, enforcement orders, and referrals to prosecutors where the business has continued after a supervisory warning.

A cross-border safeguarding matter: the structure that needed rebuilding

In a recent matter, a payments and exchange business incorporated in a non-EU jurisdiction had built a significant German user base over several years, relying on a Caribbean money services registration and a contractual arrangement with a payment aggregator. When a German banking partner reviewed the counterparty's regulatory status ahead of a new account relationship, it identified that the safeguarding arrangements did not meet BaFin's expectations for a business of that scale. We were instructed to map the full regulatory exposure, identify the fastest route to a compliant structure, and manage the banking relationship through the transition. We restructured the entity model around an EU CASP authorisation path, introduced an EMI onboarding track for the fiat rails, and prepared a voluntary disclosure framework to regularise the prior period's position with the supervising authority. The banking relationship was preserved, and the business reached a compliant operational position within the agreed transition window.

Which structure fits which operator profile?

The right safeguarding structure for a German-market business depends on three variables: the nature of the assets held (fiat, crypto, or both), the entity's existing regulatory footprint (EU-authorised, non-EU licensed, or unlicensed), and the scale and permanence of the German client relationship. The decision is not one-size-fits-all.

An EU-authorised CASP with an ESMA-compliant safeguarding model and a BaFin notification on file is the cleanest position for a business planning permanent German market presence. The timeline to reach this position – from a standing start – is a matter of months, not weeks, and depends on the completeness of the application and BaFin's current processing capacity. The capital required varies by licence category and must be verified against BaFin's current published requirements.

A passporting EU EMI with a designated German safeguarding account is the appropriate structure for a business whose primary activity is payment initiation or e-money issuance and whose crypto exposure is limited. This route is faster to deploy for a business that already holds an EMI authorisation in another EU member state and needs only to complete the BaFin notification and designate the safeguarding account.

A non-EU entity with a material German user base but no current EU authorisation faces the highest-risk position and the most work. The options are: restructure into an EU entity and apply for CASP or EMI authorisation; exit the German market pending authorisation; or accept the enforcement risk of the current position while accelerating the authorisation process. In our practice, we advise that the third option is not a commercial choice – it is a liability that grows with every day of continued operation.

CTA #2: If a prior application stalled, a bank account was closed, or an existing structure no longer fits the business, a second read can surface the structural reason and the route forward. Map your options with OBOLUS.

Self-assessment: is your German safeguarding structure sound?

Before instructing counsel, a general counsel can run a rapid internal check against the following markers. This is not a substitute for legal analysis – it is a way to identify the questions that need answers.

  • Are client funds received into an account that is legally designated as a safeguarding account at a regulated credit institution?
  • Is the safeguarding account completely separate from the firm's operational accounts?
  • Does the business have a reconciliation policy that produces a daily client-balance record that can be delivered to BaFin on request?
  • Is the entity that holds the safeguarding account itself regulated by BaFin, by an EU national competent authority under MiCA, or by a passported EMI regime with a valid BaFin notification?
  • Do the AML and Travel Rule policies reflect the current FATF and MiCA expectations as applied in Germany?
  • Has the business's scope of activity changed materially since its last regulatory review, in a way that may have moved it outside the perimeter of its current licence?

A "no" or "unsure" answer to any of these questions identifies a gap that BaFin could characterise as a supervisory finding. The earlier that gap is addressed, the lower the remediation cost.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily because they cannot satisfy their own AML and risk-management obligations with respect to the counterparty. Common triggers include: an absence of EU or national regulatory authorisation, an unclear safeguarding model, high-risk transaction patterns that the bank cannot explain to its own regulator, or a mismatch between the account's stated purpose and its actual activity. A business with a well-documented regulatory status, a clear safeguarding structure, and a compliance programme aligned to the bank's own AML framework is materially more bankable than one without those elements in place.

How can a VASP onboard with an EMI?

A VASP seeking to onboard with an EMI (electronic money institution) must demonstrate that its AML framework, Travel Rule compliance, and client-funds policies meet the EMI's own regulatory obligations. Most EU-authorised EMIs require the VASP to produce its regulatory authorisation, its AML policy, a description of its transaction monitoring controls, and an account of its safeguarding model. The process typically takes several weeks to several months depending on the EMI's onboarding queue and the complexity of the VASP's business model. Allied counsel in the relevant jurisdiction can assist with preparing the EMI onboarding package.

What does client-money safeguarding require?

Client-money safeguarding requires that funds received on behalf of clients are: held in a legally designated safeguarding account at a regulated credit institution, completely segregated from the firm's own operational funds, reconciled against client balances on a regular basis (typically daily), and protected such that they would be returned to clients ahead of the firm's general creditors in an insolvency. The specific rules depend on whether the business holds a payment institution licence, an EMI authorisation, or a CASP authorisation under MiCA – each regime applies slightly different procedural requirements to the same underlying principle.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, banking and safeguarding stack across operating, custody and payment layers before you commit to a structure – not after a supervisory finding lands. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in BaFin supervision, MiCA transition planning and cross-border payment and crypto-asset regulatory structures for inbound European mandates.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours