EMI onboarding for VASPs operating under the AIFC regime is possible, commercially viable, and structurally distinct from onboarding in most other common-law hubs – but it requires the right sequencing of licensing steps, an understanding of how the Astana Financial Services Authority (AFSA) supervises digital-asset activity, and a clear-eyed view of what a payments counterparty in or adjacent to the AIFC actually needs to see. A VASP (virtual asset service provider) that skips the preparation stage routinely discovers that its account application collapses at due-diligence review, not at the regulator's desk. This page maps the regulated basis, the practical onboarding path, and the cross-border considerations a VASP should address before it approaches any EMI in the AIFC environment.
Why EMI onboarding matters for VASPs in the AIFC
Fiat rails are the operational spine of any VASP. Without them, deposit and withdrawal flows break, institutional clients walk, and the business model contracts to on-chain-only settlement – a structural ceiling most operators cannot accept. The AIFC (Astana International Financial Centre) operates as a common-law jurisdiction within Kazakhstan, with its own courts and a bespoke regulatory regime administered by AFSA. That structure makes the AIFC attractive for digital-asset businesses that want a credible, internationally legible licence in a cost-competitive environment. The payment challenge is real, however. Not every EMI (electronic money institution) – an entity licensed to issue electronic money and execute payment transactions – will onboard a VASP, regardless of where the VASP is licensed.
In our practice, the gap between a freshly authorised AIFC VASP and a functioning fiat-rail relationship is one of the more predictable failure points in Central Asian digital-asset structuring. Operators who treat the two workstreams as sequential – licence first, then banking – lose months. Those who run them in parallel, with the right documentation, compress that timeline materially.
The loss-aversion framing matters here. Operating without stable fiat rails exposes a VASP to enforcement risk when it improvises payment channels, to reputational damage with institutional counterparties, and to the practical reality that a frozen payment account can halt operations faster than any regulatory action. The AIFC regime addresses the licensing side; the EMI relationship addresses the operational side. Both are necessary.
Readers meeting this issue for the first time should understand that the AIFC legal architecture is meaningfully different from mainland Kazakhstan law. AFSA applies English common-law principles, which gives counterparty EMIs – many of whom are themselves regulated in common-law jurisdictions – a familiar legal footing. That alignment is an asset the VASP should use actively in its onboarding narrative.
For a scoped assessment of your AIFC VASP structure and the EMI onboarding path that fits it, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options.
How does the AIFC/AFSA regulate VASPs?
AFSA authorises digital-asset businesses under a framework that covers exchange, custody, advisory and transfer/settlement activities, applying common-law principles throughout. A business seeking to operate a digital-asset trading platform or custody service inside the AIFC must obtain the relevant authorisation from AFSA before commencing regulated activity. The regime is activity-based: a firm that both exchanges digital assets and provides custody typically needs separate permissions for each regulated function, not a single omnibus licence.
The AIFC's common-law character is not a technicality. It means that contracts are governed by recognisable principles, that AFSA-authorised entities can engage sophisticated counterparties on familiar terms, and that disputes – including payment disputes – can be resolved through the AIFC Court, which applies English common-law. For an EMI conducting its own due diligence, a counterparty sitting under AFSA supervision in a common-law court system reads very differently from one operating under a civil-law or offshore-notional licence.
The AML/CFT baseline inside the AIFC draws on FATF Recommendations, including Recommendation 15 on virtual assets and the Travel Rule – the obligation to pass originator and beneficiary information with each transfer above the applicable threshold. AFSA expects VASP applicants to demonstrate a credible AML programme at the point of authorisation. A VASP that cannot show a functioning compliance infrastructure will not reach the stage of presenting itself to an EMI with a clean regulatory narrative.
One structural point that surprises inbound operators: the AIFC is jurisdictionally distinct from mainland Kazakhstan. A business authorised by AFSA is not thereby authorised to conduct regulated financial-services activity throughout Kazakhstan. The two legal regimes coexist but do not merge. For a VASP whose client base extends beyond the AIFC perimeter, that distinction has direct consequences for the scope of the licence it needs and the jurisdictions its EMI relationship must be able to support.
What does an EMI due-diligence pack actually require?
An EMI onboarding a VASP typically requires, at a minimum, proof of regulatory authorisation, a credible AML/KYC policy, audited or management accounts, a clear transaction-flow narrative, and identifiable beneficial owners who pass the EMI's own fit-and-proper assessment. That list is not exhaustive, and in practice the sequence of requests is iterative: the EMI compliance team reviews the initial pack, issues a request for further information, and the VASP responds. A disorganised or incomplete initial submission restarts the clock at each iteration.
In our cross-border practice, the single most common reason an AIFC VASP fails EMI onboarding is not the AFSA authorisation itself – which, presented correctly, reads well to a sophisticated counterparty – but the quality of the underlying compliance documentation. A policies-and-procedures manual that was drafted for the licence application and never operationalised will not survive a compliance officer's scrutiny. EMIs increasingly conduct their own on-site or remote reviews of a VASP's transaction-monitoring infrastructure. A system that logs alerts but cannot demonstrate a closed-loop resolution process is a red flag.
The beneficial-ownership question deserves specific attention in the AIFC context. Many AIFC VASPs are held through holding structures in jurisdictions outside Kazakhstan – often the BVI, Cayman, or a European holding company. The EMI's KYC process will require the full beneficial-ownership chain to be documented and the ultimate beneficial owners to be identified and verified. A chain that terminates in a nominee or an opaque trust without further disclosure will typically result in a declined application, regardless of the VASP's AFSA status.
Timing is a function of preparation. An EMI review of a well-prepared VASP pack typically proceeds over a matter of weeks; a poorly prepared submission can extend the process by months, or trigger an outright decline that requires the VASP to seek an alternative counterparty – at material cost to its operational timeline.
Which EMI profiles are most likely to onboard AIFC VASPs?
EMIs with prior experience in digital-asset client onboarding, operating in common-law or crypto-progressive regulatory environments, are the most likely category to engage constructively with an AIFC VASP. The market for crypto-friendly EMI services has consolidated in recent years, with a defined set of institutions in the UK, Lithuania, Malta, the UAE and a small number of offshore jurisdictions developing explicit VASP-onboarding programmes. Not all of them will accept a client with a Kazakhstan/AIFC nexus; some impose geographic exclusions based on their own correspondent-banking constraints.
The practical matrix works as follows. A VASP that holds AFSA authorisation, has a clean AML record, serves institutional or semi-institutional clients, and can demonstrate segregated client money handling is a materially better onboarding prospect than an unlicensed or newly registered entity with a retail-heavy client base. The former maps onto the EMI's internal risk tier in a way that makes approval commercially plausible. The latter may not clear the first-level risk screen at all.
Geography interacts with this profile analysis. An AIFC VASP whose client flows are concentrated in Kazakhstan and the Central Asian corridor may find that EMIs specialising in the region are the most natural fit – not necessarily the largest or best-known names in the European market. Conversely, a VASP with a global institutional client base may find that the AIFC authorisation, positioned as a regulated common-law entity with FATF-aligned AML, opens doors with UK or EU-based EMIs that might otherwise screen out unfamiliar jurisdictions.
In a recent engagement, a Central Asian digital-asset custody business operating under AFSA authorisation had attempted two failed onboarding processes with European payment institutions before engaging our team. We reviewed its compliance documentation, identified gaps in its transaction-monitoring evidence and its beneficial-ownership disclosure chain, restructured the presentation of its AFSA authorisation narrative, and prepared a revised submission. The business secured an account relationship with a crypto-progressive EMI within the subsequent review cycle. Scale was in the mid-seven figures of anticipated monthly flow.
How does fiat rail structure interact with cross-border tax and banking?
The jurisdiction of the EMI account, the jurisdiction of the VASP's operating entity, and the jurisdiction in which client funds are treated as received each carry distinct tax and regulatory consequences that a VASP must map before committing to a structure. An AIFC VASP that routes client deposits through an EMI account held by a non-AIFC entity may inadvertently create a taxable nexus in the EMI's jurisdiction or, worse, trigger a regulatory question about whether the receiving entity itself needs a payment licence in that jurisdiction.
Tax treatment of digital-asset receipts, conversion gains and operational income within the AIFC and Kazakhstan more broadly remains a jurisdiction-specific question that depends on the entity's structure, the nature of the income, and the applicable domestic provisions. The AIFC has its own tax regime with specific provisions for AIFC participants; mainland Kazakhstan applies different rules. Neither set of rules should be assumed to apply automatically to cross-border payment flows. We work alongside allied counsel in the relevant jurisdiction when a matter requires local-law tax advice that falls outside the AIFC perimeter.
Correspondent banking is the second structural variable. An EMI's ability to make and receive payments in a given currency corridor depends on its own correspondent relationships. An EMI that lacks a USD or EUR correspondent for the Kazakhstan corridor may accept the VASP as a client but be unable to execute the transaction types the VASP actually needs. Identifying this constraint before account opening – not after – is a material part of the pre-engagement diligence a VASP should conduct.
Safeguarding rules add a third layer. Most regulated EMIs are required to segregate client money from their own funds and to hold it in a qualifying account with an approved institution. A VASP that is itself holding client digital assets has a parallel obligation under its AFSA authorisation. The interaction between the VASP's client-asset safeguarding duties and the EMI's e-money safeguarding regime creates a documentation requirement that both sides of the relationship need to address explicitly in the account-opening process.
If a prior application stalled or an account was closed, a second review can identify the structural reason and the route back. To map the licence, banking and tax stack for your build, write to info@oboluslaw.com. Map your options.
What is the decision point for an inbound VASP considering the AIFC?
The AIFC is a well-suited domicile for a VASP that wants a credible common-law licence at a cost point below the flagship EU or UK regimes, provided the operator treats EMI onboarding as an integrated workstream, not an afterthought. The decision turns on four axes: the client profile, the currency corridors required, the operator's tolerance for a Central Asian banking counterparty versus a European one, and the timeline pressure on fiat-rail availability.
Profile A: an institutional-client VASP seeking a cost-effective common-law licence for a Central Asian or broader CIS-adjacent client base, with a clean compliance record and a well-documented ownership structure. This profile maps naturally onto the AIFC. AFSA authorisation is the primary instrument; the EMI relationship should be selected from the universe of institutions comfortable with the jurisdiction, and the onboarding pack should be led by the AFSA authorisation letter and a robust compliance-infrastructure narrative. The timeline from a complete AFSA application to a functioning fiat-rail relationship is a function of both processes running in parallel – qualitatively, a period of several months should be anticipated for the combined workstream.
Profile B: a VASP that serves retail clients globally and needs broad multi-currency settlement across EU, UK and US corridors. This profile will find the AIFC licence useful as one layer in a multi-hub structure but insufficient as a standalone solution. MiCA CASP authorisation through an EU member state, or FCA registration in the UK, may be required as a parallel instrument. The AIFC entity can hold the Central Asian and CIS-adjacent relationships; the EU or UK entity carries the European flows. EMI selection for each entity should correspond to the corridor it actually services.
Profile C: a new-market entrant with a limited compliance budget and an untested ownership structure. This profile should resolve the ownership and compliance questions first. An AFSA application submitted before those foundations are in place will not survive scrutiny, and an EMI onboarding attempt that follows a failed application faces a compounded credibility challenge. The sequencing in this case is: structure the entity cleanly, build the compliance infrastructure to a demonstrable standard, then apply to AFSA and approach EMIs in parallel.
A common assumption in the market is that a single offshore licence is sufficient to serve clients globally. That assumption is incorrect. Each jurisdiction in which a VASP's clients are located may impose its own licensing requirement, and an EMI serving the VASP in one corridor may be unable or unwilling to process flows for clients in another. The multi-hub reality of digital-asset business is not a compliance burden that can be deferred – it is a structural feature of the market that operators must build into their models from the outset.
What is the onboarding process, step by step?
A structured EMI onboarding for an AIFC VASP typically proceeds through six stages: pre-engagement diligence, documentation assembly, EMI selection and approach, submission and initial review, follow-up information requests, and account opening with limit negotiation.
Step one is pre-engagement diligence – confirming that the VASP's AFSA authorisation is in place, that the AML/KYC programme is documented and operational, and that the beneficial-ownership chain is fully mapped and ready to disclose. This stage should also include a review of the VASP's transaction-monitoring system and a confirmation that the Travel Rule obligations are being met. A VASP that cannot demonstrate Travel Rule compliance before approaching an EMI is presenting a regulatory gap that most serious counterparties will decline to overlook.
Step two is documentation assembly. The core pack typically includes the AFSA authorisation documents, a corporate structure chart with beneficial-ownership identification to the ultimate natural person, AML/KYC policies and procedures, evidence of the transaction-monitoring system and its governance, and financial projections or management accounts showing anticipated transaction volumes and flow types. An accompanying narrative – a two-to-three page executive summary that contextualises the business model and the AFSA regulatory basis for a compliance officer unfamiliar with the AIFC – materially improves the quality of the first-impression review.
Step three is EMI selection. Not all EMIs are suitable for all VASP profiles; the selection process should account for geographic coverage, currency corridors, the EMI's own VASP-onboarding track record, its capital and operational resilience, and the jurisdiction of its licence. An EMI licensed in Lithuania under MiCA transition provisions and one licensed under the UK's FCA registration regime will have different compliance cultures, different correspondent-banking capabilities, and different appetite for the AIFC nexus. Selecting the wrong counterparty wastes the preparation investment.
Steps four through six – submission, review, follow-up, and account opening – are iterative and document-intensive. The VASP should be resourced to respond to follow-up requests within days, not weeks. An EMI compliance team that waits more than ten business days for a follow-up response may deprioritise the application or close it entirely. Speed of response signals operational credibility in a way that the initial documentation cannot fully substitute for.
Objection handler: what the market gets wrong about AIFC EMI onboarding
The most persistent misconception is that AFSA authorisation automatically resolves the EMI onboarding question – that a VASP holding a regulatory licence in a credible common-law jurisdiction should expect straightforward access to payment rails. That expectation does not match operational reality.
AFSA authorisation answers the regulatory question: the VASP is a licensed entity subject to supervision. It does not answer the commercial question: whether this particular business, with this ownership structure and this compliance programme, meets the risk-appetite of a specific EMI operating its own payment licence in a different jurisdiction and subject to its own correspondent-banking constraints. Those are separate analyses, and conflating them is the most common reason VASP operators arrive at the EMI stage unprepared.
A second misconception is that the AIFC is too niche or too unfamiliar for European or UK EMIs to engage with. In our experience, a well-presented AFSA authorisation narrative – one that explains the common-law basis of the AIFC, the FATF-aligned AML requirements, and the AFSA supervision process – lands constructively with a compliance-literate counterparty. The AIFC is not a household name in every compliance department in London or Vilnius, but it is a credible jurisdiction for operators who present it correctly.
A third misconception is that the process is primarily legal rather than operational. Legal counsel is necessary to structure the entity, review the authorisation documents, and advise on the interaction between the VASP's regulatory obligations and the EMI's account terms. But the outcome of an EMI onboarding process is determined in large part by the quality of the VASP's internal compliance infrastructure and its ability to demonstrate that infrastructure credibly under review. Legal preparation without operational preparation will not succeed.
Related at OBOLUS
- Banking, payments and EMI onboarding for digital-asset businesses – the full practice overview for VASP fiat-rail structuring across jurisdictions
- PSP and acquiring agreements in Turkey – adjacent payment structuring for operators expanding into the Turkish corridor
- Fund domicile selection for early-stage founders – structuring the investment vehicle before the payment and licensing layers are built
FAQ
Why do banks close crypto company accounts?
Banks and EMIs close crypto company accounts primarily because of perceived AML/CFT risk, correspondent-banking pressure, or a mismatch between the account activity and the client's disclosed business profile. A VASP that cannot demonstrate a functioning transaction-monitoring programme, a clean beneficial-ownership structure, or consistent Travel Rule compliance gives a financial institution the compliance justification it needs to exit the relationship. Proactive disclosure and a well-maintained compliance record reduce, but do not eliminate, that risk.
How can a VASP onboard with an EMI?
A VASP seeking EMI onboarding should begin with a complete pre-engagement review: AFSA or equivalent authorisation in place, AML/KYC policies documented and operational, beneficial-ownership chain fully mapped, and transaction-monitoring evidence ready to produce. EMI selection should be based on geographic coverage, currency corridors and the institution's track record with crypto clients. The submission package should include a plain-language narrative contextualising the regulatory basis, alongside the formal authorisation documents and compliance materials.
What does client-money safeguarding require?
Client-money safeguarding requires a regulated entity to hold client funds separately from its own assets, typically in a qualifying account with an approved credit institution, in a manner that ensures those funds are protected in an insolvency event. For an AIFC VASP, safeguarding obligations under the AFSA regime apply to client digital assets; for the EMI, e-money safeguarding rules apply to fiat balances. Both sets of obligations must be documented and maintained independently. The interaction between the two layers should be addressed explicitly in the account-opening documentation.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – so the structure you build is one you can actually bank and operate. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when the stakes are highest. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP authorisation, EMI onboarding strategy and cross-border regulatory compliance for digital-asset businesses in the AIFC and adjacent jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.