Operating a digital-asset business that holds client money without a clear legal basis for doing so is one of the faster routes to enforcement action, frozen payment rails and lost banking relationships. Client funds safeguarding – the obligation to hold, segregate and account for client money in a defined legal structure – is a condition that follows the regulated activity, not the domicile chosen for marketing purposes. In the Seychelles, the applicable regime sits under the Financial Services Authority and the Virtual Asset Service Provider framework, and it intersects directly with EMI onboarding (the process of securing an electronic money institution banking relationship), fiat rails (the correspondent-banking and payment-processing infrastructure connecting crypto flows to the traditional financial system) and the cross-border obligations that arise whenever users or banking partners sit in a different jurisdiction from the licensed entity. This page sets out the regulated basis for client-money safeguarding in the Seychelles, the practical process for inbound businesses, and the points where the analysis turns on your specific structure.
What Is the Legal Basis for Client Funds Safeguarding in the Seychelles?
Client funds safeguarding in the Seychelles is governed by the Financial Services Authority (FSA) and the Virtual Asset Service Provider framework that sits under it, which together define how a licensed VASP must hold, segregate and account for any client money it touches. The FSA is the primary regulator for non-bank financial services in the Seychelles, and its VASP (virtual asset service provider) regime reflects the FATF Recommendation 15 baseline that most leading offshore jurisdictions have now adopted. Safeguarding is not optional or a matter of internal policy. It is a condition of the licence.
Under the applicable regime, a VASP holding client money – whether in fiat or in digital assets – is expected to maintain clear segregation between client funds and its own operating capital. The principle is straightforward: client money is not the firm's money. It cannot be commingled with operational accounts, pledged as collateral without client consent, or exposed to the firm's insolvency. In practice, this means dedicated trust or safeguarding accounts, robust reconciliation procedures and audit trails that the FSA can inspect.
What the Seychelles framework does not do is replicate the granular prescriptive rules found in, say, MiCA's treatment of asset-referenced token reserve requirements or the FCA's client-money sourcebook. The regime is principles-based. That creates flexibility for inbound businesses – but it also means the onus is on the operator to design a structure the FSA will accept, and that banks and payment partners will recognise. In our practice, we see businesses underestimate that second element consistently.
Who Needs a VASP Licence and Safeguarding Structure in the Seychelles?
Any business providing virtual asset services to clients from or through a Seychelles entity requires FSA registration or licensing under the applicable VASP provisions – and that obligation brings the safeguarding requirement with it automatically. The relevant activity categories include exchange services (crypto-to-fiat and crypto-to-crypto), transfer services, custody, brokerage and the administration of virtual asset instruments. If your business touches any of these activities and is structured through a Seychelles entity, the safeguarding obligation applies regardless of where your end clients are located.
This matters most for two operator profiles. First, there is the offshore holding and licensing entity – a business that licenses in the Seychelles to serve a global client base, often pairing the FSA registration with operating entities in higher-activity jurisdictions. Second, there is the inbound structuring play – an operator moving from an unregistered position to a compliant structure after a bank account closure or a correspondent bank refusal. Both profiles face the same safeguarding baseline. The difference lies in how quickly the structure needs to be operational and how the cross-border layer – where users are, where banking lives, where tax accrues – is handled.
A common misreading of the position: the Seychelles FSA VASP registration is not a passport. It authorises the regulated activity within the scope of the Seychelles regime. It does not, by itself, permit the business to solicit or serve retail clients in the EU (which would engage MiCA and ESMA oversight), in the UK (which would engage FCA registration), or in Singapore (which would engage the MAS Payment Services Act). Businesses that treat a single offshore registration as a licence to operate globally are exposed – not just to the foreign regulator, but to their own banking relationships, which will conduct exactly this analysis when reviewing onboarding documentation.
Practical note: We regularly advise operators whose banking applications were declined not because the licence was invalid, but because the compliance documentation did not demonstrate that the safeguarding structure matched the regulated perimeter. The FSA registration alone is not the answer a Tier-1 EMI is looking for. It is the starting point.
How Should a Seychelles VASP Structure Client Money Safeguarding?
A compliant safeguarding structure for a Seychelles VASP has three components: account segregation, reconciliation and audit readiness. Getting all three right before the first client funds are received is the professional standard. Retrofitting a safeguarding structure after client money has already moved through the operating account is a regulatory and reputational problem, and one we see more often than it should occur.
Account segregation means holding client money in accounts that are legally and operationally distinct from the firm's own working capital. In practice, this usually involves a dedicated trust account or a designated safeguarding account with a bank that acknowledges the trust character of the funds. The bank's acknowledgement matters: if the firm's bank becomes insolvent, the trust designation affects the treatment of those funds in the insolvency estate. Operators that open a standard corporate account and use internal ledger entries to track client balances are not safeguarding in any meaningful legal sense.
Reconciliation is the daily or real-time matching of the internal ledger – what the firm's system shows as client balances – against the external bank or custodian statement. A gap in reconciliation is a gap in the safeguarding structure. Regulators, auditors and EMI partners all treat unexplained reconciliation differences as a compliance deficiency, and in a VASP context those gaps can arise quickly when on-chain and off-chain positions are both in scope.
Audit readiness is the documentation layer: clear policies, evidence of segregation, reconciliation records and board-level oversight. The FSA expects this infrastructure to be in place before the licence is granted, not constructed in response to an inspection. For inbound businesses, the practical implication is that the safeguarding structure is a pre-condition of the application, not a post-approval task.
How Does EMI Onboarding Work for a Seychelles VASP?
Securing an EMI relationship – the banking or payment-institution account that connects the VASP's fiat operations to the broader payments infrastructure – is consistently the hardest practical step for Seychelles-registered digital-asset businesses, and the safeguarding structure is the single factor that most determines whether the onboarding succeeds. EMIs and correspondent banks apply their own due-diligence frameworks. They are asking the same question the FSA is asking: are client funds held in a structure that is legally and operationally distinct from the firm's money?
The EMI onboarding process for a VASP typically involves the following stages. First, the business must have its FSA licence or registration in place, or at least have received a conditional approval that the EMI can review. Second, it must produce a compliance pack that includes the safeguarding policy, the account structure diagram (showing the legal relationship between the trust account, the operating account and the on-chain custody wallet), the AML/KYC framework and the beneficial ownership disclosure. Third, the EMI's compliance team will review the pack and, in most cases, conduct a call or a site visit before issuing a decision.
Timelines vary. A well-prepared compliance pack – one that answers the questions the EMI will ask before they are asked – shortens the onboarding process materially. An incomplete pack restarts the clock. In our cross-border practice, we have seen onboarding take anywhere from several weeks to several months depending on the EMI's current risk appetite for the Seychelles flag and the operator's sector. Crypto exchange businesses, in particular, face elevated scrutiny. That scrutiny is manageable. It requires documentation, not a different structure.
The cross-border dimension here is significant. A Seychelles-licensed VASP that wants to accept EUR or GBP deposits will need fiat rails that run through an EU or UK EMI, and those institutions will apply MiCA or FCA standards to the counterparty regardless of where it is licensed. The Seychelles safeguarding structure must be defensible under those standards, not just under the FSA's own rules. In our practice, we design safeguarding documentation that addresses the primary regulator and the banking partner's jurisdiction simultaneously.
CTA: The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options with our team at OBOLUS, or write to info@oboluslaw.com to start the conversation.
What Cross-Border Obligations Apply When Users or Banking Sit Outside the Seychelles?
A Seychelles VASP is not operating in a jurisdictional vacuum. The moment it accepts clients from the EU, routes payments through a UK EMI or custody a client's assets with a US-regulated custodian, the legal analysis expands well beyond the FSA framework. Managing that expansion is the central challenge for any operator using the Seychelles as a licensing base for an internationally active business.
The EU position is the most immediately material for most operators. MiCA, the EU's Markets in Crypto-Assets Regulation supervised by ESMA and national competent authorities, applies to entities offering crypto-asset services to clients in the EU regardless of where the entity is established. A Seychelles VASP soliciting EU retail clients without CASP authorisation in at least one EU member state is operating outside the MiCA perimeter. The safeguarding structure in the Seychelles does not cure that gap. It is a separate question.
The FATF Travel Rule is a further cross-border obligation. The Travel Rule (the FATF obligation to pass originator and beneficiary data alongside a virtual asset transfer) applies to VASPs in most major jurisdictions at thresholds that vary by regime. A Seychelles VASP sending or receiving transfers from counterparts in FATF-member jurisdictions must have Travel Rule compliance infrastructure that is recognised by the counterpart institution. In our practice, we regularly identify Travel Rule gaps in businesses that have a sound safeguarding structure but have not completed the messaging-protocol layer that underpins compliant cross-border transfers.
Tax interaction is the third cross-border element. The Seychelles has no corporate income tax on international business, which makes it a structurally efficient base for operations with limited local nexus. However, substance requirements in the operator's home jurisdiction, controlled foreign corporation rules in shareholder jurisdictions and withholding on cross-border payments can all affect the net position. We work alongside tax counsel in the relevant jurisdictions to ensure the legal structure matches the commercial flow before it is built.
What Are the Most Common Safeguarding Mistakes Seychelles VASPs Make?
The most expensive safeguarding mistakes in our experience are structural, not operational. They are made at the incorporation and licencing stage, before a single client account is opened, and they create problems that surface months later when the EMI application fails or when a banking partner conducts a periodic review and closes the account.
The first mistake is treating safeguarding as a compliance formality. Operators prepare a safeguarding policy for the licence application and then do not implement it operationally. The policy says client funds are held in a designated trust account. The operational reality is that client receipts hit the company's general account and are swept to a separate account only at month end. That gap – between policy and practice – is precisely what an EMI's compliance team will find.
The second mistake is the commingling of digital-asset custody with fiat safeguarding. A VASP that holds client crypto in an omnibus hot wallet and client fiat in a trust account has two separate safeguarding obligations and two separate audit trails. Treating them as one – or failing to document the relationship between them – creates confusion in a regulatory review and can cause a banking partner to treat the entire structure as opaque.
The third mistake, and the one most directly tied to the offshore-licence myth, is assuming that an FSA registration resolves the banking relationship. Banks and EMIs conduct their own legal analysis. An operator that approaches an EMI with an FSA licence and no further documentation is asking the EMI to do the legal work on the operator's behalf. EMIs decline that invitation. The documentation must make the case.
Which Operator Profile Benefits Most from a Seychelles Safeguarding Structure?
Not every business is well-served by a Seychelles licensing and safeguarding structure. The question is whether the Seychelles FSA regime matches the operator's risk profile, user base and banking requirements. Three profiles illustrate the decision point.
Profile A – the offshore holding layer. A digital-asset fund or custody business that has its primary regulatory presence in a major jurisdiction (an EU member state under MiCA, Singapore under MAS, or the UAE under VARA) and uses a Seychelles entity for the offshore holding, IP or intercompany licensing layer. The safeguarding obligation in the Seychelles applies to the activities conducted from the Seychelles entity. Provided the primary regulated activity is domiciled in the principal jurisdiction, this is a clean structure. The key risk is inadvertent activity at the Seychelles level that triggers FSA licensing requirements without the safeguarding infrastructure in place.
Profile B – the inbound VASP. A digital-asset business with an existing unregistered position that needs to regularise and secure banking. The FSA VASP framework is a credible route, with a process timeline that is generally measured in weeks rather than months for a well-prepared application. The safeguarding structure must be in place before the application is filed. The banking onboarding runs in parallel with the licensing process, not after it. The key risk is an incomplete compliance pack that extends the timeline and allows a banking window to close.
Profile C – the EU-facing exchange. A crypto exchange that wants to serve EU clients using a Seychelles base. This is the profile most often misled by the offshore-licence myth. The Seychelles FSA registration does not authorise EU client-facing activity under MiCA. For this profile, the Seychelles entity may serve a useful structuring role, but a CASP authorisation in at least one EU member state is required for the EU-facing business. In our cross-border practice, we map the full licence stack before the structure is committed.
A Practice Note: Safeguarding Structure and EMI Onboarding
In a recent matter, a fintech company holding a Seychelles FSA VASP registration approached OBOLUS after its third EMI application had been declined. The company had a compliant safeguarding policy on paper. The issue was that its account structure diagram showed client fiat receipts flowing through an undesignated corporate account before manual transfer to the safeguarding account – a process dependent on a single treasury officer and running on a weekly cycle. We restructured the account architecture so that client receipts credited directly to the designated safeguarding account at the point of receipt, with the operating account funded by a separate fee-sweep mechanism. We also updated the compliance documentation to reflect the revised structure and to address the Travel Rule messaging protocol the earlier applications had not covered. The following application succeeded at the first review stage.
Is a Single Offshore Licence Enough to Operate Globally?
A common assumption among inbound digital-asset businesses is that an FSA VASP registration in the Seychelles, or any comparable offshore registration, is sufficient to operate a global client-facing business. It is not. The offshore registration is the legal basis for the activity conducted from the Seychelles entity. It does not address the regulatory obligations that attach to the clients' location, the banking partners' jurisdiction or the custody infrastructure's domicile.
Each of those three dimensions brings its own regulatory layer. EU clients bring MiCA. UK-based EMI rails bring FCA financial-promotion rules and MLR obligations on the counterpart. A US-domiciled custodian may bring FinCEN or state money-transmitter licensing considerations. The safeguarding structure in the Seychelles must be designed with those layers in mind from the outset, not retrofitted when a compliance officer at a bank or EMI raises the question.
The practical answer is a licence stack: an FSA VASP registration for the Seychelles-layer activities, paired with CASP authorisation in the EU for EU-facing activity, FCA registration in the UK for UK-facing elements, and so on. That is more complex than a single registration. It is also the structure that actually works when the banking relationship, the regulator and the counterpart EMI each apply their own analysis. We map that stack before the first entity is incorporated.
CTA: If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Write to info@oboluslaw.com or message us at t.me/oboluslaw. Map your options.
Self-Assessment: Is Your Seychelles Safeguarding Structure Ready?
Before approaching an EMI or filing an FSA licence application, an operator should be able to answer the following questions affirmatively. If any answer is uncertain, the structure requires attention before the application is filed.
- Client receipts credit directly to a designated safeguarding or trust account, not to the company's general operating account.
- The safeguarding account is held with a bank that has acknowledged the trust character of the funds in writing.
- A daily reconciliation procedure matches internal ledger balances against external account statements, with documented sign-off.
- The account structure diagram clearly shows the separation between client money accounts, the operating account and any on-chain custody wallets.
- The AML/KYC framework addresses the Travel Rule for virtual asset transfers to and from counterpart VASPs.
- The compliance pack addresses the regulatory requirements of both the FSA and the EMI's home jurisdiction.
- Board-level oversight of the safeguarding structure is documented in board minutes or a governance policy.
An operator that can answer each of these questions with documentation to support the answer is in a materially stronger position for both the FSA application and the EMI onboarding than one relying on policy statements alone.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital-Asset Businesses – our full practice covering fiat rails, EMI relationships and payment licensing across jurisdictions.
- EMI Onboarding for VASPs in Georgia – the Georgian EMI regime as a complementary banking and payment gateway for offshore-licensed businesses.
- AIF for Digital Assets in Turkey – alternative investment fund structuring for digital-asset exposure in the Turkish regulatory context.
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts most commonly because the compliance documentation does not demonstrate a legally compliant safeguarding structure, a clear regulatory basis for the activity, or an adequate AML/KYC framework. A VASP licence alone is not sufficient. The bank's own compliance team will apply its institutional risk framework independently of the regulator's licensing decision, and gaps in the safeguarding structure or Travel Rule compliance will frequently produce a refusal or a closure even where the licence is valid.
How can a VASP onboard with an EMI?
A VASP onboards with an EMI by presenting a compliance pack that includes the licence or registration documentation, a safeguarding policy that matches the operational account structure, an AML/KYC framework, Travel Rule compliance documentation and a clear beneficial-ownership disclosure. The EMI will conduct its own due diligence against its internal risk appetite. A well-prepared pack that anticipates the EMI's questions – particularly around client-money segregation and cross-border payment flows – shortens the process and improves the probability of a first-review approval.
What does client-money safeguarding require?
Client-money safeguarding requires, at minimum, three operational elements: segregation of client funds in accounts legally distinct from the firm's own money; daily reconciliation of internal ledger balances against external account statements; and documented governance, including board-level oversight and a written safeguarding policy. In a cross-border digital-asset context, the safeguarding structure must also address the on-chain custody layer and the Travel Rule obligations that apply when funds move between the VASP and counterpart institutions in other jurisdictions.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise crypto exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – and we have seen the banking and EMI onboarding challenges that follow when that mapping is skipped. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP licensing, client-money safeguarding frameworks and cross-border regulatory compliance for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.