EST · MMXXVI
Home/Jurisdictions/Malta/Corporate bank account opening in Malta: Legal Requirements for Businesses
Banking, Payments & EMI Onboarding

Corporate bank account opening in Malta: Legal Requirements for Businesses

Corporate bank account opening in Malta. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Corporate bank account opening in Malta is a regulated process, not an administrative formality. For a digital-asset business, the outcome turns on entity structure, licensing status under the Malta Financial Services Authority (MFSA) regime, and the institution's own risk appetite for virtual-asset exposure. With the transition from the prior Virtual Financial Assets (VFA) framework to the EU's MiCA (Markets in Crypto-Assets Regulation) CASP authorisation model now underway, Malta's banking community is recalibrating its onboarding criteria accordingly. This page maps the legal requirements, the practical process, and the cross-border variables that determine whether your application succeeds.

Why Banking Remains the Hard Problem for Crypto Entities in Malta

Obtaining a Maltese banking relationship for a digital-asset company is harder than obtaining the licence itself. Banks operating under MFSA supervision carry their own regulatory obligations – robust AML/CFT programmes, risk-appetite frameworks and capital obligations – and a high-risk customer like a VASP (virtual asset service provider) or a MiCA CASP adds regulatory exposure that many institutions price as unacceptable. The result is systematic de-risking: accounts closed, applications declined, and businesses left with fiat rails that do not match their operational footprint.

In our practice, we see this most acutely at the intersection of the transition period. An entity that held a legacy VFA registration is now either migrating toward full CASP authorisation under MiCA or operating under a transitional permission. Banks ask which regime applies, what the transitional status means for the entity's obligations, and whether the ultimate authorisation will survive. Without a clear, documented answer to each question, the application stalls before a compliance officer ever reviews the business plan.

The cross-border angle compounds the difficulty. The Maltese banking market is not large. Many operators licensed in Malta serve users across the EU via MiCA passporting, hold custody assets in one jurisdiction, and bank in another. Each institution evaluates the full group – not just the Maltese entity – and the compliance profile of any affiliate in a higher-risk jurisdiction raises questions for the local bank, regardless of the Maltese entity's own standing.

Operators we advise routinely underestimate how much of the banking decision is made at a group-level risk committee, not at the branch desk of the local compliance team. Preparing for that committee review – with a full regulatory map, a governance summary and a clear beneficial-ownership chain – is the work that precedes a successful application.

A Maltese company applying for a corporate bank account must be duly incorporated under the Maltese Companies Act, hold a registered address, and have appointed the directors and beneficial owners recorded with the Malta Business Registry. For a digital-asset business, the licensing layer sits on top of that corporate foundation.

Under MiCA and the applicable MFSA provisions, a company providing crypto-asset services to clients in the EU must hold or be in the process of obtaining CASP authorisation. A company that was registered as a VFA service provider under the prior regime may continue to operate during the transitional period, but banks are free to apply their own risk criteria to that interim status. Some institutions will onboard a fully authorised CASP. Fewer will onboard an entity in transition. Almost none will onboard an entity that has neither registration nor authorisation and is relying on the argument that its activity falls outside the regulated perimeter.

Beyond the licence, banks assess the quality of the entity's AML/CFT programme. Malta's obligations under the FATF Recommendations – and specifically FATF Recommendation 15, which addresses virtual-asset risks – require the entity to maintain customer due-diligence procedures, transaction-monitoring controls, and a compliance function adequate for its risk profile. A bank's onboarding questionnaire will probe each of these. If the company's AML policy is a template document with no substance behind it, the bank's compliance team will decline the account regardless of the licence status.

Which Institutions Serve Digital-Asset Businesses in Malta?

The Maltese banking market consists of a small number of domestically licensed institutions and several branches of larger European groups. Not all of them actively onboard digital-asset companies. The institutions that do typically operate tiered onboarding: a standard corporate account for entities with limited virtual-asset exposure, and a more intensive process – including enhanced due diligence and sometimes a direct dialogue between the bank's compliance head and the company's compliance officer – for exchanges, custodians and token-issuers.

Beyond traditional banks, EMI (electronic money institution) onboarding is an increasingly used alternative. An EMI licensed under the applicable EU payment-services regime can hold client funds in a safeguarded account, issue IBANs, and facilitate SEPA transfers. For many crypto businesses, an EMI relationship provides functional fiat rails without requiring the deeper AML relationship a bank account demands. The EMI is not a bank – it does not lend – but for a business whose primary need is to receive euro payments, execute payouts and move treasury between jurisdictions, an EMI account often serves the operational purpose.

The practical reality we see in our cross-border practice is that most operators end up with a layered solution: a primary banking relationship in one jurisdiction, an EMI account for day-to-day payment flows, and a treasury or custody account in a third. Malta can play any of those roles, but it is rarely the only piece of the architecture.

How Does the Onboarding Process Work for a Crypto Company?

Corporate bank account opening in Malta follows a documented KYC/AML intake process, the depth of which scales with the institution's classification of the applicant's risk profile. A virtual-asset business will almost always be classified as high-risk, triggering enhanced due diligence regardless of its licence status or track record.

The typical documentation package the institution will require includes: certified constitutional documents; a current certificate of good standing; a complete beneficial-ownership register with supporting identity documentation for each UBO above the relevant threshold; audited financial statements (or management accounts for a newly incorporated entity); a detailed business-plan narrative covering the products offered, the geographies served, the anticipated transaction volumes and the customer segments; and the entity's full AML/CFT policy, including its transaction-monitoring procedures and its sanctions-screening protocol.

For a digital-asset business, the bank will typically add a technology questionnaire covering the platforms used, the custody model, the wallet architecture, and the identity-verification process applied to the company's own clients. MFSA-licensed or MiCA-authorised entities are expected to provide their authorisation documentation and any supervisory correspondence that bears on the scope of the licence.

Timeline varies by institution and by the completeness of the application. A well-prepared package submitted to an institution that actively serves the sector can progress through initial review in a matter of weeks. An incomplete application – missing UBO documentation, a generic AML policy, or no response to the technology questionnaire – will pause at each deficiency, extending the process materially. In our practice, we have seen applications stretch across several months where the root cause was a preventable documentation gap rather than a fundamental risk-profile problem.

CTA #1: The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. For a scoped assessment of your Malta banking options, contact OBOLUS at info@oboluslaw.com. Or map your options with our team.

What Cross-Border Variables Affect the Outcome?

Banking in Malta is almost never a purely Maltese question. The group structure, the jurisdiction of incorporation of any holding entity, the nationalities of the beneficial owners, and the geographies in which the business operates all feed the institution's risk model.

A Maltese CASP that passports into Germany, France and the Netherlands under MiCA faces a different risk-appetite assessment than a Maltese entity serving only institutional counterparties in the DIFC. The former is in scope for the full MiCA regulatory posture, including the whitepaper and marketing-communication requirements. The latter may be treated as a more limited-exposure relationship by the bank, particularly if the DIFC-facing business is conducted through a separately licensed ADGM or DIFC entity.

The tax dimension intersects directly with banking. A Maltese holding company that routes dividends from a subsidiary in a higher-risk jurisdiction may attract questions about substance – whether the Maltese entity has genuine management and control, a physical presence, and staff with decision-making authority. Banks increasingly ask about this, because a shell Maltese entity with no local substance raises money-laundering red flags under the FATF framework, regardless of whether its commercial purpose is legitimate. The answer to that risk is genuine economic substance in Malta, not just a registered address.

Beneficial-owner nationality also matters. Owners or directors who are nationals of jurisdictions on the FATF grey list or the EU's list of high-risk third countries will face individual enhanced due diligence. That is not a bar to onboarding, but it lengthens the process and requires a more detailed personal history and source-of-funds narrative.

A Practical Illustration: Blocked Fiat Rails at a Critical Juncture

In a recent banking matter, a payments company holding a Maltese VFA service provider registration had its primary bank account closed with minimal notice during the institution's portfolio risk review. The company's euro settlement rails went dark mid-cycle, creating an operational crisis. We were engaged to map alternative institution options, reframe the compliance narrative for the new application, and prepare a response to the original bank's closing notification to preserve a potential administrative remedy. Within a matter of weeks, the company had a functioning EMI relationship as an interim bridge and a formal banking application in progress at a second institution with a documented appetite for digital-asset businesses. The original bank's decision was not reversed, but the company's fiat operations resumed without a withdrawal window forming for its own clients.

What Does EMI Onboarding Require for a Digital-Asset Business?

EMI onboarding for a digital-asset business applies the same risk-based due-diligence principles as a bank application, but the regulatory relationship is different. An EMI licensed under the applicable EU payment-services framework is supervised for payment-services compliance, not for the full breadth of banking regulation. That distinction narrows but does not eliminate the compliance overhead a crypto business must satisfy on intake.

The Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer) applies to the VASP or CASP client, not to the EMI itself. But the EMI will ask to see how the business implements the Travel Rule, because the business's own compliance posture bears on the EMI's exposure as a regulated counterparty. An EMI that processes fiat in and out for a crypto exchange that cannot demonstrate Travel Rule compliance is an EMI with a compliance problem of its own.

Client-money safeguarding is the critical structural requirement from the EMI's perspective. Funds received from a business's clients must be held in a designated safeguarded account, segregated from the EMI's own funds, and covered by an appropriate insurance or guarantee arrangement. For a crypto business that holds fiat on behalf of its own users, the EMI's safeguarding model directly determines how those funds are protected. We advise clients to map the safeguarding structure before executing any EMI agreement, because the contractual terms – particularly around segregation, insolvency waterfall and withdrawal rights – are where operational risk concentrates.

CTA #2: If a prior banking application stalled or an account was closed, a second read can surface the structural reason and the route back. Write to OBOLUS at info@oboluslaw.com or reach us via t.me/oboluslaw. Alternatively, map your options directly.

Common Mistakes That Delay or Derail Applications

Most failed or delayed applications share a recognizable set of root causes. Understanding them before submission is the most efficient form of preparation.

The first and most common mistake is submitting before the licensing position is clear. A bank's compliance team will not approve an account for an entity that cannot state its regulatory status with precision. If the entity is in the MiCA transitional window, the application must explain exactly what that means, what the timeline to full authorisation looks like, and what supervisory correspondence has been exchanged with the MFSA. Vague answers on licensing trigger automatic escalation.

The second mistake is a generic AML policy. A policy that reads as a template – with placeholder references to "the applicable regulations" and no specifics about how the business identifies, monitors and reports suspicious activity – signals to the bank's compliance officer that the compliance function is cosmetic. A policy tailored to the specific product (exchange, custody, lending), the specific customer segments and the specific geographies is far more persuasive.

Third: incomplete UBO chains. For group structures with holding entities in BVI, Cayman or other offshore jurisdictions, every layer of the ownership chain must be documented and verified. Leaving a link in the chain undocumented – even at a level below the usual disclosure threshold – raises the suspicion that the gap is intentional.

Fourth: no banking strategy before incorporation. We regularly advise clients who incorporated in Malta, obtained their licence, and then discovered that the institution they had informally identified as their banking partner had tightened its appetite for digital-asset businesses in the intervening period. The banking strategy should precede or run in parallel with the incorporation and licensing process, not follow it.

A Common Assumption Worth Examining

A common assumption among operators entering Malta is that a single licence – VFA, MiCA CASP, or an offshore registration from an earlier jurisdiction – is sufficient to serve clients globally and access banking in any market. It is not. MiCA passporting covers the EU/EEA. It does not authorise activity in Singapore, Hong Kong or the United States. Each of those markets has its own regime: the MAS Payment Services Act, the SFC VATP licensing regime, and the US federal and state money-transmitter licensing structure, respectively. A bank in Malta evaluating a business that claims global operations will ask about regulatory coverage in every jurisdiction where the business has material user exposure. If the answer is "we rely on our Maltese licence for everything," the bank's compliance team will identify the gap and either price it into the risk decision or decline outright. The correct answer is a jurisdiction-by-jurisdiction map of coverage, with allied counsel engaged in each market where local licensing applies.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily because of risk-appetite decisions made at the portfolio level, not always because of anything the individual company has done wrong. The core drivers are: the institution's own AML exposure from servicing high-risk customers; supervisory pressure from the national regulator; and the cost of maintaining enhanced due diligence on an account that generates limited fee income relative to the compliance overhead it creates. Entities with strong documentation, a credible compliance function and a clear licensing position are materially less vulnerable to this outcome.

How can a VASP onboard with an EMI?

A VASP onboarding with an EMI follows the same risk-based intake process as a bank application: entity documentation, beneficial-ownership verification, AML/CFT policy review, and a technology questionnaire covering the business's own client-verification and transaction-monitoring procedures. The EMI will also assess how the VASP implements the Travel Rule. An EMI relationship provides functional fiat rails – SEPA, IBANs, safeguarded client-money accounts – without the full breadth of a banking relationship, and it is often a more accessible first step for a newly licensed digital-asset business.

What does client-money safeguarding require?

Under the applicable EU payment-services regime, an EMI must hold funds received from clients in a designated safeguarded account, segregated from the EMI's own operational funds. That account must be held at a credit institution or invested in secure, liquid assets, and covered by an appropriate insurance or guarantee arrangement. For a crypto business using an EMI as its fiat-rail provider, the practical implication is that the contractual terms governing that safeguarded account – particularly the insolvency waterfall and the withdrawal conditions – require careful review before execution.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence, banking and payment stack across the operating, custody and payment layers before you commit to a structure. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in MFSA and MiCA licensing requirements and banking-access strategy for inbound digital-asset businesses in Malta and the EU.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours