EST · MMXXVI
Home/Jurisdictions/Lithuania/Client funds safeguarding in Lithuania: Legal Requirements for Businesses
Banking, Payments & EMI Onboarding

Client funds safeguarding in Lithuania: Legal Requirements for Businesses

Client funds safeguarding in Lithuania. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Client funds safeguarding in Lithuania: Legal Requirements for Businesses

Operating a payments or crypto business in Lithuania without a correctly structured client-funds safeguarding arrangement is one of the fastest routes to a frozen banking relationship. Client funds safeguarding – the legal obligation to hold customer money separately from the firm's own assets and in a prescribed manner – sits at the centre of the Payment Services Act (the Lithuanian implementing legislation under the EU payment services directives) and, for businesses that also handle virtual assets, under the Bank of Lithuania supervised VASP (virtual asset service provider) regime now transitioning to full MiCA (Markets in Crypto-Assets Regulation) CASP authorisation. The analysis below sets out what the law requires, how inbound businesses typically structure compliance, and where the cross-border interaction with tax and banking most commonly produces legal risk.

This page addresses the decision facing a general counsel or founder whose business holds client money – fiat or crypto – through a Lithuanian entity, and who needs to understand what safeguarding demands in practice, not in theory.

What does client funds safeguarding actually mean under Lithuanian law?

Safeguarding is the legal requirement that a licensed payments or electronic-money institution hold client funds in a ring-fenced structure – either in a designated safeguarding account at a credit institution, in covered government bonds, or via an insurance policy – so that those funds are protected in the event of insolvency. Under the Bank of Lithuania's supervisory posture, the obligation is not optional for any entity authorised as a payment institution or EMI (electronic money institution). It applies to the full float of client money at all times.

Lithuania implemented the EU payment services directives consistently with the European Banking Authority's safeguarding guidelines, which distinguish between the segregation method (a dedicated account at a credit institution, legally separated from the firm's operational accounts) and the insurance or guarantee method (a qualifying policy that covers the equivalent amount). Most businesses licensed in Lithuania use the segregation method in practice, because the insurance route requires qualifying underwriters that are difficult to engage at scale for crypto-adjacent businesses.

The Bank of Lithuania does not apply a softer read of these obligations to businesses with a crypto or virtual-asset component. If a payment institution or EMI holds fiat on behalf of users – even where those users are primarily crypto traders – the safeguarding rules apply in full. We regularly advise businesses that assumed their crypto wrapper placed them outside the payment-services perimeter; the analysis almost always points the other way.

Which businesses operating in Lithuania must safeguard client funds?

Any entity authorised by the Bank of Lithuania as a payment institution or EMI must safeguard client funds that it holds in the course of providing payment services or issuing electronic money. That category is broader than many operators assume.

A crypto exchange that also operates a fiat on-ramp – accepting euro deposits for later conversion to Bitcoin or a stablecoin – is holding client funds within the scope of the payment services regime. A custodian that settles trades in euro on behalf of clients is similarly exposed. A VASP that issues its own stable coin analogue, if that instrument meets the definition of electronic money, will require EMI authorisation and full safeguarding compliance.

Under the MiCA transition, operators that previously held only a Bank of Lithuania VASP registration for crypto-to-crypto services face a materially wider net. Once MiCA CASP authorisation applies, the scope of regulated services expands, and so does the indirect pressure on payment infrastructure. In our cross-border practice, we see operators underestimate this expansion consistently – particularly where the Lithuanian entity was set up as a lean holding vehicle and the payment activity was expected to run through a third-party EMI.

The practical test: if your Lithuanian entity touches client fiat at any point in the transaction chain – even briefly during settlement – a payment-services authorisation question arises, and with it a safeguarding obligation.

CTA #1 – If you are assessing whether your Lithuanian structure triggers a safeguarding obligation, the analysis turns on the precise transaction flow, not the marketing description of your product. Map your options with our team before the Bank of Lithuania raises the question for you.

How does the segregation method work in practice?

The segregation method requires the licensed entity to open one or more designated client-funds accounts at a credit institution – meaning a bank or building society authorised within the EEA – and to deposit all client money into those accounts promptly, holding it there until it is due to the client or transmitted to a payee. The account must be titled in a way that makes clear it holds funds belonging to clients, not the firm. The firm's own operational money must never co-mingle with it.

For Lithuanian-licensed businesses, accessing a safeguarding account at a Lithuanian credit institution is often the most straightforward compliance route. In practice, however, it is also one of the most contested steps. Lithuanian commercial banks apply heightened due-diligence standards to payment institutions and EMIs with crypto-related business models. Onboarding timelines that might be a matter of weeks for a conventional payment business can extend substantially for a crypto-adjacent operator, and some institutions decline outright.

This is where the cross-border dimension becomes acute. Operators we advise routinely explore safeguarding account arrangements with EEA credit institutions in other member states – most commonly in Germany, the Netherlands, or the Baltic peers – holding the account outside Lithuania while the licence itself sits with the Bank of Lithuania. That structure is legally permissible under the EEA financial-services framework, but it requires careful documentation: the Bank of Lithuania expects to be satisfied that the safeguarding account is readily accessible, ring-fenced in the legally required manner, and subject to the firm's annual audit. A safeguarding arrangement with a non-EEA institution is not available under the standard regime.

The annual reconciliation and audit obligation compounds the operational burden. The licensed entity must be able to demonstrate, at any time, that the balance of the safeguarding account matches the client funds liability. For businesses with high transaction volumes or real-time settlement models, this requires robust internal reconciliation infrastructure from day one.

How does client-money safeguarding interact with the Lithuanian VASP and MiCA regime?

The Lithuanian VASP regime, supervised by the Bank of Lithuania, was historically distinct from the payment-services regime – a relatively light-touch AML/CFT registration rather than a prudential authorisation. Under MiCA, that distinction collapses. CASPs providing exchange, transfer or custody services will require authorisation, and the prudential and operational requirements are materially more demanding than the prior VASP registration.

For client-funds safeguarding, the MiCA CASP regime introduces its own custody and safeguarding expectations that run alongside – and interact with – the payment-services rules where both apply. A business that holds crypto assets in custody must satisfy the MiCA custody requirements, while any fiat component triggers the payment-services safeguarding regime. A business that holds both simultaneously – as most crypto exchanges do – must maintain parallel compliance structures.

In our practice, we see this dual-layer obligation create the most difficulty for operators that designed their Lithuanian structure around the pre-MiCA VASP registration model. The corporate entity may be the right vehicle. The operational infrastructure – segregated accounts, custody arrangements, internal reconciliation, audit – is almost always underbuilt for the CASP standard.

The Travel Rule (the FATF obligation to pass originator and beneficiary data alongside a virtual-asset transfer) sits alongside the safeguarding requirements as a parallel AML/CFT obligation. The Bank of Lithuania expects both to be operational before a CASP authorisation is granted. A safeguarding structure that is technically compliant but sits inside an AML programme that has not addressed the Travel Rule will not pass supervisory review.

What is the cross-border banking and fiat rails challenge for Lithuanian operators?

Lithuania's position as an EU CASP-authorisation jurisdiction is strategically attractive – a Bank of Lithuania licence passports across the EU and EEA, giving a single authorisation access to the full single-market user base. That passporting benefit is real. The banking access challenge is equally real and runs in the opposite direction.

Banks in the major EU markets – Germany, France, the Netherlands, Spain – have their own internal credit-risk policies for payment institutions and EMIs with crypto-related business. A Lithuanian CASP or EMI that passports into those markets cannot compel a local bank to open an account. The firm must either maintain its banking relationship in Lithuania, negotiate EEA-wide banking independently, or operate through a third-party EMI or BaaS provider that itself holds the relevant banking relationship.

Each of those routes carries legal structuring questions. Using a third-party EMI to hold client fiat while a Lithuanian EMI holds the licence creates a principal-agent relationship that the Bank of Lithuania will examine on authorisation review. The passthrough arrangement must be documented, the safeguarding obligations mapped to the correct entity, and the client disclosures structured to reflect who is actually holding the money.

Operating without a resolved fiat-rails strategy before applying for authorisation is a common structural mistake. The Bank of Lithuania will ask, as part of the application review, how the applicant proposes to safeguard client funds and with whom. An answer that relies on a banking relationship that has not been secured in principle is unlikely to satisfy.

For businesses sitting between a Lithuanian licensed entity and, for example, a UAE or Singapore operating hub, the question is which entity holds client money and where it is safeguarded. The answer determines which regime's safeguarding rules apply, and which regulator has supervisory authority over the arrangement. A cross-border structure that splits the holding and the service provision across two jurisdictions will face questions from both regulators.

CTA #2 – If a prior application stalled on the banking or safeguarding question, or if a correspondent account was closed after authorisation, the structural reason is usually identifiable. Map your options with our team to identify the route back.

How has this played out in practice?

In a recent matter, a crypto payments operator had obtained a Lithuanian EMI authorisation but structured its client-funds account with a payment institution rather than a credit institution. The arrangement passed initial review but was flagged on the first supervisory cycle. We were instructed to re-engineer the safeguarding structure under time pressure: we identified a qualifying EEA credit institution prepared to open a dedicated safeguarding account, drafted the updated client disclosure and internal audit methodology, and supported the operator through the Bank of Lithuania's variation process. The firm maintained its authorisation and its payment rails without interruption.

Which safeguarding structure fits which operator profile?

The choice of safeguarding method and structure depends on the operator's business model, transaction volume, geographic ambitions and banking access. Three operator profiles recur in our practice.

Profile A – EU-focused EMI or payment institution with a crypto on-ramp: this operator holds primarily euro client funds. The segregation method at an EEA credit institution is the standard path. The key risk is banking access. Indicative resolution time once a qualifying account is secured is a matter of weeks for the compliance documentation, but banking negotiations can extend the timeline materially. The primary legal risk is the gap between authorisation grant and first compliant safeguarding account – the Bank of Lithuania expects the account to be operational at or before licence commencement.

Profile B – MiCA CASP with combined fiat and crypto custody: this operator must satisfy both the MiCA custody requirements and the payment-services safeguarding regime simultaneously. The compliance infrastructure is more demanding, and the audit requirements interact. The legal risk sits in the interface between the two regimes: an operator that satisfies one but not the other remains non-compliant. In our cross-border practice, we map both regimes against the operational model before the authorisation application is submitted.

Profile C – Inbound operator passporting into the EU via a Lithuanian CASP: this operator may have existing banking in a non-EU jurisdiction and is building the EU footprint through Lithuania. The challenge is building a qualifying EEA safeguarding account structure without an established EU banking relationship. Using a third-party BaaS or EMI as an intermediary is a common bridge, but it requires detailed contractual and disclosure structuring. The legal risk is regulatory characterisation: if the arrangement looks like the Lithuanian entity is providing a licence shell while the real business runs offshore, the Bank of Lithuania will not be satisfied.

What are the most common safeguarding mistakes for crypto businesses in Lithuania?

The following errors appear with regularity in businesses we are instructed to advise after the fact.

Mixing operational and client funds. The prohibition on co-mingling is absolute. Businesses that use a single account for both client receipts and operational payments – even temporarily, even for settlement efficiency – are in breach from the moment the co-mingling occurs. The Bank of Lithuania treats this as a fundamental failure, not a technical deficiency.

Relying on a non-EEA institution for the safeguarding account. A safeguarding account at a US or UAE bank does not satisfy the EEA credit-institution requirement under the payment-services regime. Operators that onboard banking in their preferred jurisdiction first and ask the legal question later face a rebuild under supervisory pressure.

Failing to reconcile continuously. The safeguarding obligation is live at all times, not only at month-end. Businesses with real-time settlement flows that reconcile only periodically create a structural gap. The Bank of Lithuania's audit expectations reflect a continuous-reconciliation model.

Assuming a VASP registration satisfies the full obligation. A Bank of Lithuania VASP registration under the pre-MiCA regime was an AML/CFT registration, not a payment-services authorisation. It did not and does not create a safeguarding compliance framework. An operator that holds fiat client money under a VASP registration alone is operating without the required authorisation for that activity.

A common assumption we encounter is that a single offshore licence – whether in the BVI, Cayman or another light-regulation centre – is sufficient to serve EU clients, hold EU client fiat, and pass EU regulatory review. It is not. The EU's regulatory perimeter follows the service and the client, not only the entity's jurisdiction of incorporation. A Lithuanian-incorporated CASP passporting into the rest of the EU must satisfy EU-level obligations at every layer.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily because internal credit-risk and compliance policies treat virtual-asset businesses as elevated-risk counterparties. The reasons include AML exposure concerns, difficulty assessing the underlying client base, and regulatory uncertainty around the business model. A payment institution or EMI with a crypto component can reduce closure risk by providing clear transaction-flow documentation, a robust AML programme, a structured safeguarding arrangement, and a business model that aligns with the bank's own regulatory obligations. Proactive legal preparation before account opening is consistently more effective than remediation after closure.

How can a VASP onboard with an EMI?

A VASP seeking to onboard with an EMI as a fiat-rails provider must demonstrate a compliant AML/KYC programme, clear client-fund flows, and a business model the EMI's compliance team can assess confidently. The onboarding process typically involves a detailed questionnaire, transaction-flow mapping, ownership and control documentation, and a review of the VASP's supervisory status. Under the MiCA regime, a CASP authorisation from the Bank of Lithuania or another EU national competent authority materially strengthens the onboarding case relative to a light-touch registration. Engaging legal counsel to structure the presentation and negotiate the terms of the relationship reduces timeline and improves outcomes.

What does client-money safeguarding require?

Client-money safeguarding requires a licensed payment institution or EMI to hold all client funds in a ring-fenced structure – typically a designated account at a qualifying EEA credit institution – entirely separate from the firm's own assets. The obligation is continuous: the safeguarding account must reflect the full client-funds liability at all times, and the firm must reconcile the two positions on an ongoing basis. An annual audit of the safeguarding arrangement is required. The Bank of Lithuania expects the safeguarding structure to be operational at or before the commencement of the licensed activity, not after the licence is granted.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions – including the full stack of Lithuanian and EU payment-services authorisation – on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice. We map the licence, banking and safeguarding stack across the operating, custody and payment layers before you commit. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in EU payment-services authorisation, Bank of Lithuania VASP and CASP supervision, and client-funds compliance for cross-border digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours