Correspondent banking access in Malta is one of the most operationally critical – and most frequently underestimated – legal problems facing digital-asset businesses that choose the island as their regulatory home. As MiCA (the EU's Markets in Crypto-Assets Regulation) reshapes European crypto supervision under ESMA and national competent authorities, Malta's position as a licensed gateway to EU payment rails has sharpened. But the licence alone does not open a bank account. The regulated status, the ownership structure, the AML posture, and the way the business presents itself to a correspondent bank all determine whether fiat rails ever connect. This page maps the legal requirements, the process, and the decision points a business must work through to secure correspondent banking access in Malta.
Why banking is the hard part of a Malta crypto licence
Correspondent banking access in Malta depends on far more than holding a valid crypto licence issued by the Malta Financial Services Authority (MFSA). A VASP or CASP (Crypto-Asset Service Provider, the MiCA-era licence category) that passes MFSA authorization may still find that every EU clearing bank declines to open or maintain an account. The reason is structural: correspondent banks set their own risk appetite independently of the regulator. MFSA authorization demonstrates regulatory standing; it does not compel a private institution to extend credit or payment services.
The practical consequence is acute. Without a settlement account at a licensed credit institution or EMI (electronic money institution), a CASP cannot process client deposits or withdrawals in fiat, cannot pay staff and suppliers in euros, and cannot meet the client-money safeguarding rules that MFSA enforces. Operating without those fiat rails risks enforcement action, frozen balances and reputational damage that closes further banking options. The loss exposure is not theoretical – in our practice, we regularly advise businesses that launched in Malta, built their technology stack, and then discovered that banking was the single point of failure for the entire model.
The process above describes the standard regulatory path. The banking reality is different. To map the specific banking options available to your entity type and ownership structure, contact OBOLUS at Map your options.
What is the MFSA regulatory basis for crypto-banking interaction?
Malta's crypto regulation now operates on two legal layers. The prior VFA (Virtual Financial Assets) framework – which required a licensed VFA agent and structured MiCA-predecessor obligations – is transitioning to the EU-wide CASP authorisation regime under MiCA. Businesses that held VFA registration under the MFSA framework must either convert to a CASP authorisation or restructure. Either way, the MFSA is the competent authority, and the MiCA CASP authorisation opens EU passporting: a single authorization is, in principle, valid across every EU and EEA member state.
That passporting right is the commercial argument for Malta as a base. A Malta-authorized CASP can serve clients in Paris, Amsterdam and Warsaw from a single regulated entity. But the passporting right is a regulatory construct. The payment layer – the actual movement of euros through the SEPA system – requires a banking relationship in a jurisdiction whose central bank is part of the TARGET2 infrastructure. Malta is a eurozone member. A Malta-domiciled company with a Maltese credit-institution account can clear directly within SEPA. That is the combination operators are seeking, and it is the combination that requires careful legal preparation to achieve.
Who needs correspondent banking access in Malta?
Any licensed crypto business that holds or moves client fiat needs a banking relationship. The operator profiles that most frequently require correspondent banking in Malta fall into three groups.
First, crypto exchanges and trading platforms that accept euro deposits from retail or institutional clients. These businesses must hold client money in a segregated account at a credit institution or in eligible money-market instruments; the MFSA and MiCA together impose that safeguarding requirement. A correspondent bank is the first step in that chain.
Second, custody providers that hold digital assets for third parties and need to receive or return fiat on settlement. Even where custody is primarily on-chain, client activity routinely generates fiat flows – subscription, redemption, staking income distributed in euros – and each of those flows requires a bank.
Third, token issuers launching an ART (asset-referenced token) or EMT (e-money token) under MiCA. Both token categories carry reserve-holding requirements: the issuer must maintain qualifying liquid assets backing the outstanding token supply. Those reserves must sit in regulated bank accounts. An EMT issuer that cannot open a bank account cannot legally issue tokens. The regulatory and commercial consequences are simultaneous.
How AML posture and the Travel Rule affect bank risk appetite
Correspondent banks reject crypto business accounts primarily on AML grounds, not on product grounds. Understanding that distinction is essential. A bank's correspondent-risk policy is driven by its own regulator – typically the European Central Bank for eurozone institutions, alongside the relevant national authority – and by FATF Recommendation 15, which requires financial institutions to apply risk-based measures to virtual-asset service providers as a distinct high-risk customer category.
The Travel Rule (the obligation to transmit originator and beneficiary data with every qualifying virtual-asset transfer) compounds this. A correspondent bank onboarding a CASP must satisfy itself that the CASP has a functioning Travel Rule compliance program, because failures in that program create downstream exposure for the bank itself. In practice, a bank's due-diligence questionnaire for a crypto business runs to scores of items: the transaction monitoring system, the sanctions screening vendor, the on-chain analytics tool, the KYC framework for the CASP's own clients, the ownership and control structure, and the jurisdictions in which the CASP is active.
A business that approaches a correspondent bank with a freshly issued MFSA licence but no documented AML framework, no named compliance officer, and no sanctions-screening infrastructure will be declined. The licence confirms regulatory standing; the compliance infrastructure is what the bank actually evaluates. We have seen this sequence repeatedly: a well-structured regulatory application succeeds at the MFSA, and then the same business fails on banking because it treated compliance as a box-ticking exercise rather than an operational system.
What does the banking onboarding process look like for a Malta CASP?
Banking onboarding for a Malta-licensed CASP typically follows a multi-stage sequence, each with its own timeline and documentation requirements.
The first stage is pre-qualification. Before submitting a formal account application, the business should assess which credit institutions and licensed EMIs in Malta or the wider EU accept crypto-business clients. This is not public information. The pool of willing institutions is materially narrower than the total number of licensed banks, and it shifts as institutions revise their risk appetite. A structured pre-qualification approach – engaging institutions whose stated policy is compatible with the applicant's business model – avoids wasted time on formal applications that will be declined at the first review gate.
The second stage is documentation preparation. A full correspondent-banking application for a crypto business typically requires: the MFSA authorisation certificate and the applicable licence scope; a detailed business plan including projected transaction volumes, average transaction size and geographic distribution of clients; the full corporate ownership chain to ultimate beneficial owner, with supporting identity documentation; AML/CFT policies and procedures in final, board-approved form; a description of the transaction monitoring and sanctions-screening systems; and, where the business serves institutional counterparties, a sample onboarding framework for those counterparties.
The third stage is the bank's own due diligence, which may include questionnaires, interviews and site visits. The timeline for this stage varies considerably by institution and is not standardised. Some Malta-based credit institutions operate structured crypto-client onboarding programs with defined review windows; others treat each application ad hoc. In our cross-border practice, we regularly prepare clients for this review by stress-testing the application against the bank's known policy positions before submission.
The fourth stage is account opening, which triggers the operational AML requirements on both sides: the client begins reporting obligations to the bank, and the bank begins its ongoing monitoring obligations.
If a prior banking application stalled or was withdrawn, the structural reason matters. A second application to the same institution without addressing that reason will fail on the same ground. Contact OBOLUS at Map your options to identify the route back.
Is an EMI account a viable alternative to a correspondent bank?
A licensed EMI (electronic money institution) account is a recognized and frequently used alternative to a direct correspondent-bank relationship for Malta-based CASPs. EMIs hold an EU-passported licence under the Electronic Money Directive; they can hold client funds, issue payment accounts, and facilitate SEPA transfers. For a CASP that cannot secure a direct bank account, an EMI relationship provides the operational fiat rail needed to accept and return client funds.
The legal considerations for EMI onboarding mirror those for bank onboarding: the EMI will conduct its own AML due diligence, assess the CASP's compliance posture, and evaluate the transaction-monitoring infrastructure. The EMI is itself subject to regulatory oversight – by the MFSA in Malta, or by the competent authority in whichever EU state issued its licence – and carries its own supervisory risk if it onboards non-compliant counterparties.
There are structural limits to an EMI relationship that a board-level decision should account for. An EMI account is not the same as a credit-institution account: it does not provide access to credit facilities, does not always offer the full range of correspondent-banking services (trade finance, FX hedging, letters of credit), and may impose transaction-volume limits or client-type restrictions. For a CASP with institutional counterparties or significant transaction volume, an EMI account may be a starting position while a direct bank relationship is developed in parallel – not a permanent substitute.
How does the cross-border structure affect banking access?
A Malta CASP rarely operates in legal isolation. The entity in Malta is typically one node in a structure that includes an operating company, a technology entity, a custody vehicle, and perhaps a fund or holding entity in another jurisdiction. Each of those layers creates banking complexity.
A correspondent bank onboarding the Malta entity will look through the entire structure to identify the beneficial owners, the origin of funds flowing into the Malta entity, and the jurisdictions in which the group is active. An ownership chain that passes through a jurisdiction with elevated FATF risk ratings, or a holding company in a zero-disclosure territory, will generate additional due-diligence requirements and may be disqualifying. The tax structure matters too: a group that has engineered its flow of funds to minimize Maltese substance risks failing the bank's economic-substance assessment, which is increasingly standard in EU correspondent-banking diligence.
Malta's own tax regime interacts with this. Malta operates a full-imputation corporate tax system that, in practice, can produce effective tax rates materially below the headline rate for qualifying structures. That feature is commercially attractive. But it requires that the Malta entity has genuine operational substance – directors resident in Malta, real decision-making on the island, proper corporate governance records – because the tax authority, the MFSA and the correspondent bank all assess substance independently. A shell entity with a Malta licence but no real presence will fail on all three of those assessments.
Micro-matter: recovering banking access after de-risking
In a recent matter, a digital-asset payments business licensed in Malta had its primary bank account closed with short notice following a de-risking review by the correspondent bank. The closure was not triggered by a regulatory event – the MFSA licence remained valid – but by the bank's internal reassessment of its crypto-client portfolio. The business had no secondary banking relationship and faced an immediate operational crisis: client settlements were blocked and payroll could not be processed.
We were engaged within days of the closure notice. We identified two structural issues in the business's original banking documentation – an undisclosed beneficial-owner layer and an out-of-date AML policy that predated a significant product expansion – that had created latent risk for the bank. We worked with the client to remediate both issues, prepare a revised documentation package, and approach alternative credit institutions in Malta and a licensed EMI operating across the EU. The business restored a functional fiat rail within a matter of weeks, and subsequently secured a direct bank account with a different institution on a stronger compliance foundation.
Which banking structure fits which CASP profile?
The right banking configuration for a Malta CASP depends on the business model, the transaction profile and the ownership structure.
A startup CASP with a narrowly scoped licence, modest transaction volumes and a clean, simple ownership structure is best served by a direct approach to Malta-based credit institutions that have defined crypto-client programs, supplemented by an EMI account as an operational backup. The timeline to account opening, assuming documentation is complete, is a matter of weeks to a few months depending on the institution.
A scaling CASP or exchange with institutional counterparties, cross-currency flows and significant transaction volumes needs a direct correspondent-bank relationship with a eurozone credit institution, Travel Rule compliance infrastructure certified against a recognized standard, and possibly a secondary relationship in a second EU jurisdiction for operational resilience. The preparation and onboarding timeline is longer, and the compliance documentation requirements are substantially higher.
A token issuer – particularly an EMT issuer under MiCA – must have its reserve-account banking in place before tokens are issued. This is a hard regulatory constraint, not a commercial preference. The bank holding the reserves will require the same due-diligence package as for any other crypto client, plus specific representations about the reserve management policy and the redemption mechanism. Planning the banking before the token launch – not after – is the only workable sequence.
A common assumption: one licence is sufficient for global operations
A common assumption among businesses entering Malta is that a single MFSA CASP authorisation is sufficient to serve clients in every jurisdiction where the business operates. MiCA passporting does create an EU-wide right, but it does not extend beyond the EU/EEA. A Malta CASP serving clients in the United States is subject to US federal and state requirements – potentially including SEC, CFTC, FinCEN, and state money-transmitter licensing – regardless of its EU status. Serving clients in Singapore or Hong Kong adds MAS or SFC analysis. Serving clients in the Gulf may bring VARA or ADGM/FSRA considerations into scope.
The practical effect on banking is direct. A correspondent bank that discovers a CASP is serving clients in jurisdictions for which it holds no licence will close the account, because the bank's own AML exposure extends to the unregulated activity. Disclosing the full geographic scope of the business at the outset – and having the licence stack to support it – is both the legal obligation and the banking prerequisite. We map the licence, banking and tax stack across operating, custody and payment layers before our clients commit to a structure, precisely because the cost of retrofitting is dramatically higher than the cost of designing correctly.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital-Asset Businesses – the full practice area overview for fiat-rail access across jurisdictions
- EMI Onboarding for VASPs and Regulated Entities – the specific process for connecting a licensed VASP to an EU electronic money institution
- Fund Manager Licensing in the Bahamas – licensing options for digital-asset fund structures in an offshore common-law jurisdiction
FAQ
Why do banks close crypto company accounts?
Banks close crypto accounts primarily because of risk-appetite reassessments, not regulatory events. A correspondent bank may de-risk an entire client category if its own supervisor applies pressure, if internal models flag the portfolio as disproportionately high-risk, or if a specific client's compliance documentation is found to be deficient. The closure typically does not reflect any finding by the MFSA or another crypto regulator – a valid licence does not insulate an account from a bank's commercial decision. Businesses that build a secondary banking relationship before a crisis are substantially better positioned to manage a de-risking event.
How can a VASP onboard with an EMI?
A VASP onboarding with a licensed EMI follows a structured due-diligence process that mirrors bank onboarding. The EMI will require the VASP's regulatory authorisation, its full ownership and beneficial-owner documentation, board-approved AML and compliance policies, a description of its transaction-monitoring and sanctions-screening systems, and projected transaction volumes. The EMI's own regulatory obligations – under the Electronic Money Directive and applicable AML directives – mean it carries direct exposure for any compliance failure by a VASP client. Preparation of a complete, coherent documentation package before approaching the EMI materially shortens the review timeline.
What does client-money safeguarding require?
Under MiCA and MFSA rules, a CASP that holds client funds must segregate those funds from its own assets and hold them in qualifying accounts at a licensed credit institution or in eligible money-market instruments. The safeguarding obligation applies from the moment client funds are received. Practical implementation requires a dedicated safeguarding account, clear contractual arrangements with the holding institution, and an internal reconciliation process that the MFSA can audit. An EMT issuer has additional reserve requirements: backing assets must meet composition and liquidity standards set out under the applicable MiCA provisions.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence stack across operating, custody and payment layers before you commit – because the cost of a structural error surfaces at the banking stage, not the regulatory stage. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory and Compliance Analyst – specialising in MFSA, MiCA CASP authorisation and correspondent-banking access for inbound digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.