De-risking and account closure are the most acute operational threat facing Seychelles-domiciled crypto businesses today
A de-risking event (the unilateral withdrawal of banking or payment services by a financial institution, typically without a right of appeal) can strand a digital-asset business overnight. For companies incorporated in the Seychelles – a jurisdiction widely used for offshore crypto structuring – the risk is heightened because correspondent banks increasingly flag Seychelles-origin entities on geographic risk grounds alone, before any compliance review of the actual business. The practical consequence: fiat rails freeze, client settlements stall, and the corporate structure that was meant to enable the business instead disables it. This page sets out the regulated basis for de-risking defence in the Seychelles context, the process for rebuilding banking access, and the cross-border structuring decisions that determine whether the problem recurs.
With regulators in the major banking hubs tightening their expectations of correspondent exposure (the risk a bank takes on by processing payments for customers of a foreign institution), Seychelles entities face a dual challenge: they sit in a jurisdiction with a lighter-touch regulatory posture, and they operate in an asset class that most correspondent banks still classify as elevated risk. The combination is manageable – but it requires a deliberate, layered response.
Why are Seychelles entities disproportionately targeted by de-risking?
Geographic risk scoring is the first filter most correspondent banks apply, and Seychelles consistently appears on internal watch-lists maintained by European and North American banking groups. This is not a legal finding of wrongdoing – it is an automated risk-management posture. The result is that a Seychelles company holding a legitimate business licence may receive an account closure notice from an EU or UK payment institution with no substantive explanation and no path to a formal hearing.
The underlying drivers are structural. FATF's mutual evaluation process and its published lists of jurisdictions under enhanced monitoring create reference points that banks translate into policy. Seychelles has periodically appeared in discussions about beneficial-ownership transparency and AML/CFT compliance gaps. Even where a specific entity has strong controls, the institutional risk appetite of a large correspondent bank will often override the individual compliance picture.
There is a second, less-discussed driver: regulatory ambiguity around the specific activities being conducted. A Seychelles entity that holds a Securities Dealer Licence issued by the Financial Services Authority Seychelles (FSA) but also handles client crypto assets may find that the bank's own legal team cannot categorize its business clearly. Unclear regulatory classification produces the same outcome as a negative classification – refusal or termination.
What does the Seychelles regulatory regime actually cover?
The Financial Services Authority Seychelles (FSA) is the primary regulator for non-bank financial services, including entities engaged in securities dealing and fund management. Seychelles does not operate a dedicated VASP (virtual asset service provider) licensing regime equivalent to those found in the UAE under the VARA regime or in the EU under MiCA (the Markets in Crypto-Assets Regulation). This regulatory gap is itself a banking risk.
When a correspondent bank or EMI (electronic money institution) reviews a Seychelles crypto entity for onboarding, it will ask what regulated activity licence the entity holds and which supervisor could be called in the event of a compliance concern. A company operating under a general commercial licence, or even a Securities Dealer Licence, may not have a satisfying answer to either question. The bank's risk team – which needs to justify the relationship to its own regulator – will then decline on a "no adequate regulatory hook" basis.
The practical implication: Seychelles is an appropriate domicile for holding structures, intellectual-property vehicles, and certain fund entities. It is a more difficult domicile for the operational entity that touches client fiat money, processes payments, or acts as exchange counterparty. The account-closure problem is frequently a symptom of a structural mismatch between where the entity is incorporated and where its regulated activity should sit.
To map the right entity and licence layer for your Seychelles structure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard analysis. Your facts – the activity type, the user base, the banking relationship – change the answer materially.
What is the immediate response protocol when an account is closed?
The first 72 hours after receiving a de-risking notice determine how much of the remediation is recoverable. Most account closure notices in the EMI and payments-institution sector are issued under a contractual termination right that requires only a short notice period – often between 30 and 60 days. That window is the working timeline for the response.
Four steps matter immediately. First, preserve documentation: the full account history, the compliance submissions made during onboarding, any enhanced-due-diligence materials provided, and the closure notice itself. These records are the basis for any formal objection or regulatory complaint. Second, identify the regulatory basis for the closure. Some jurisdictions impose a duty on payment institutions to provide reasons; others do not. Whether the FCA in the UK, the relevant national competent authority in an EU member state, or the MAS in Singapore applies depends on where the EMI or bank is regulated.
Third, assess the complaint mechanism. In the UK, regulated payment institutions are subject to Financial Ombudsman Service jurisdiction for certain business complaints, and the FCA expects firms to have a complaint-handling procedure. In the EU, national competent authorities supervise payment institutions' conduct obligations. Filing a formal complaint does not guarantee reinstatement but it creates a documented record that is relevant to any subsequent regulatory escalation.
Fourth – and this is where we see operators lose the most time – do not immediately apply to a new provider using the same entity and the same documentation package. The information that caused the first refusal will trigger the same outcome. The documentation must be restructured: a clear regulatory narrative, an updated compliance framework description, and, where applicable, evidence of a pending or completed licensing application in a more recognised jurisdiction.
Is restructuring the only lasting solution?
Restructuring the entity layer is frequently the only durable solution when a Seychelles entity cannot obtain banking on its own regulatory footprint. This does not mean abandoning the Seychelles structure – it means adding an operational layer in a jurisdiction whose regulatory status is recognized by the target banking counterparties.
The most commonly used supplementary jurisdictions in our cross-border practice are those with CASP (crypto-asset service provider) authorisation under MiCA within the EU; Payment Services Act licensing in Singapore under MAS; and VASP or comparable registration in the UK under the FCA's MLR (Money Laundering Regulations) framework. Each of these carries a regulatory credential that most European and Asian correspondent banks recognize and can assess.
A Seychelles holding entity paired with an EU-licensed CASP operating subsidiary is a structure we see regularly. The CASP entity holds the banking relationship, processes client fiat, and passports across the EU/EEA. The Seychelles parent holds intellectual property, may act as the investment vehicle, and sits outside the EU's direct supervisory perimeter. This is not a compliance evasion – it is a structural response to the legitimate commercial need for banking access, executed within the applicable regulatory regime.
The AIFC/AFSA regime in Kazakhstan is also used as an intermediate layer for businesses with a CIS or Central Asian user base, given its common-law framework and growing banking connectivity. For businesses in the MENA corridor, an ADGM/FSRA authorisation or a VARA licence in Dubai can serve the same anchoring function.
One structural caution applies consistently: the operating entity and the regulated entity must be aligned. A Seychelles holding company that "routes" client funds through an EU-licensed subsidiary, while the actual client-facing activity remains in the unregulated parent, will not pass regulatory scrutiny. The activity and the licence must be co-located.
How does a crypto business actually onboard with an EMI?
EMI onboarding for a crypto business is a structured compliance process, not a standard account-opening exercise. The EMI – whether operating under an EU-passported e-money authorisation, an FCA-registered status, or a comparable instrument – must satisfy its own regulator that it has conducted appropriate due diligence on every business customer. For a crypto-asset client, that bar is materially higher than for a standard fintech.
The process typically unfolds in stages. A preliminary assessment determines whether the EMI's risk appetite includes the applicant's activity type – exchange, custodian, lending desk, or fund. This stage is often handled by a relationship manager but backed by the EMI's compliance team. Many crypto businesses fail here not because of their compliance quality but because the EMI has already reached its capacity for crypto-segment exposure.
Assuming the activity type is acceptable, the formal onboarding pack for a Seychelles-domiciled crypto entity should include: corporate documents certified to the relevant standard; a detailed business description that maps the specific activities to a regulatory classification; evidence of AML/KYC policy and procedure; a description of the technical and operational controls around client-asset handling; a clear description of who the end clients are and in which jurisdictions they are located; and, critically, an explanation of which regulatory licence applies to the activity and who the applicable supervisor is.
The Travel Rule (the FATF obligation to pass originator and beneficiary data with a transfer) is now a live question in most EMI onboarding reviews. An applicant that cannot demonstrate Travel Rule-compliant infrastructure will face delay or refusal, regardless of jurisdiction. This is one of the AML/CFT cross-cutting requirements that applies consistently across the major banking hubs, even where the applicant's home jurisdiction has not fully implemented it.
What does client-money safeguarding require in this context?
Client-money safeguarding is a regulated obligation in every major financial centre, and its absence is a material banking risk. For a Seychelles-incorporated entity that manages client fiat balances – whether as an exchange, a payment intermediary, or a lending platform – the question is not only whether the funds are technically safe but whether the regulatory architecture demonstrates that they are safe to the satisfaction of a banking counterparty.
Under the EU's payment and e-money frameworks, safeguarding means holding client funds in a designated account at a credit institution, separated from the firm's own funds, subject to audit requirements and regulatory reporting. Under MiCA, CASP authorisation includes specific own-funds and safeguarding requirements tied to the activity category.
A Seychelles entity that holds client fiat without the benefit of a safeguarding framework will find that no regulated EMI or bank will act as the safeguarding institution. The bank needs to know that the client funds in the account are legally protected – segregated in law, not merely in accounting practice. Without a regulatory regime that mandates and audits that segregation, the bank cannot represent to its own supervisor that the relationship is low-risk.
In our cross-border practice, we regularly advise on the interaction between the Seychelles holding layer and the safeguarding obligations of an operating subsidiary in a regulated jurisdiction. The two are not incompatible – but they require explicit structural drafting, clear inter-company agreements, and a compliant account designation that satisfies both the operating regulator and the banking counterparty.
If a prior application stalled or an account was closed, a structural second read often surfaces the root cause. Contact OBOLUS at info@oboluslaw.com to begin that assessment.
A recent illustration
In a recent matter, a payments company with a Seychelles holding structure found its primary EMI account closed after the EMI's parent bank withdrew its correspondent banking relationship with all offshore-domiciled crypto clients. The company had compliant AML/KYC procedures and a functioning compliance function. The closure was geographic, not conduct-based. We reviewed the entity structure, identified that the client-facing activity sat in the Seychelles entity rather than a regulated operating subsidiary, and advised on the addition of an EU-licensed CASP layer. Within a business quarter, the restructured operating entity had secured a new EMI relationship and banking access had been restored. The Seychelles holding company remained in place as the IP and investment vehicle.
The structural mistake that repeats
A common assumption among operators building on a Seychelles base is that a single offshore incorporation, perhaps accompanied by a general FSA licence, is sufficient to operate globally and access banking in any jurisdiction. That assumption is wrong, and the account-closure problem is how businesses discover it.
The offshore licence provides corporate flexibility and a low-cost formation. It does not provide a regulatory credential that EU, UK, Singapore or Hong Kong banks can rely upon when satisfying their own AML/CFT obligations. The gap between "we have a licence" and "we have a licence that the bank's compliance team recognizes" is where most Seychelles-based crypto businesses encounter their banking crisis.
The solution is a multi-layer structure: the Seychelles entity serves the function it is genuinely suited for, and the operating layer that requires bank access sits in a jurisdiction whose regulatory status is legible to the target banking community. We see this pattern across exchanges, custodians, OTC desks, and fund structures. The specifics vary; the principle does not.
Related at OBOLUS:
- Banking, Payments and EMI Onboarding for Digital-Asset Businesses – full practice overview covering EMI access, payment licensing and fiat rail strategy across jurisdictions
- Client Funds Safeguarding from a Cross-Border Perspective – analysis of safeguarding obligations and how they interact with offshore holding structures
- Digital-Asset Custody Licensing in Luxembourg – jurisdiction guide for businesses considering an EU-anchored custody or CASP entity
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because they cannot satisfy their own regulators that the relationship is adequately supervised. The most common triggers are geographic risk scoring (offshore domicile flagged as elevated risk), inability to identify a recognized regulatory licence covering the specific activity, AML/CFT concerns including Travel Rule gaps, and correspondent-bank policy withdrawals that affect entire customer categories regardless of individual compliance quality. Conduct-based closure is less common than structural-risk closure.
How can a VASP onboard with an EMI?
Onboarding with an EMI requires a documented compliance package that addresses the EMI's regulatory obligations toward its own supervisor. This means a clear description of the VASP's regulated activities and applicable licence, a current AML/KYC policy, Travel Rule-compliant transaction monitoring, a client-asset description mapping fiat and crypto flows, and evidence of the beneficial ownership structure. An offshore-only VASP will need to demonstrate a regulatory anchor that the EMI's compliance team can assess and record in its own due-diligence file.
What does client-money safeguarding require?
Client-money safeguarding requires that client fiat balances are held in a designated, segregated account at a regulated credit institution, separate from the firm's own funds, subject to audit and regulatory reporting obligations. The specific requirements vary by regime – under MiCA, CASP authorisation includes defined own-funds and safeguarding rules; under EU payment and e-money frameworks, segregation and safeguarding audits are mandatory. An entity without a regulatory regime that mandates segregation will find it difficult to obtain a banking or EMI relationship for client-facing fiat activity.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence, banking, and payment stack across operating, custody, and payment layers before you commit – not after a crisis has started. To discuss your structure, contact info@oboluslaw.com or reach us via t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP licensing, AML/CFT frameworks, and cross-border regulatory structuring for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.