EST · MMXXVI
Home/Jurisdictions/Switzerland/EMI onboarding for vasps in Switzerland: Legal Requirements for Businesses
Banking, Payments & EMI Onboarding

EMI onboarding for vasps in Switzerland: Legal Requirements for Businesses

Emi onboarding for vasps in Switzerland. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

For a virtual asset service provider operating in or from Switzerland, the practical question is not whether fiat rails matter – it is which licensed counterparty will provide them and on what terms. EMI onboarding in Switzerland sits at the intersection of FINMA (the Swiss Financial Market Supervisory Authority) oversight, anti-money-laundering obligations under the applicable AML/CFT regime, and the commercial risk-appetite of European and Swiss electronic money institutions. Without a functioning bank or EMI relationship, a VASP's licence is an operational shell: compliant on paper, paralysed in practice.

This page addresses the legal and structural requirements that govern EMI onboarding for VASPs under Swiss law, the cross-border dimension when the EMI is licensed in another jurisdiction, and the decision points that determine whether a relationship survives due diligence. It draws on the FINMA regulatory regime, the applicable AML provisions, and the Payment Services Act framework in neighbouring EU jurisdictions where Swiss-licensed VASPs commonly seek fiat connectivity.

Why Swiss VASPs Face Persistent Banking Friction

Swiss VASPs face a structural tension: Switzerland has one of the world's most respected regulatory regimes for digital assets under FINMA, yet access to fiat rails remains a persistent operational constraint. The root cause is not Swiss law – it is the risk-appetite of individual EMIs and correspondent banks applying their own de-risking policies, often without reference to the quality of the VASP's underlying compliance programme.

FINMA operates a token taxonomy that distinguishes payment tokens, utility tokens and asset tokens. A VASP operating under this taxonomy, whether as a fintech licence holder, a banking licence holder, or through an SRO/AML affiliation, carries a regulated status that most EU EMIs formally accept. The gap is not legal recognition. It is the commercial underwriting that follows: transaction-monitoring policies, expected volume profiles, the origin of customer funds, and the VASP's own KYC standards.

In our practice, VASPs that present a complete regulatory and compliance file at the outset – including a documented AML/CFT policy aligned to FATF Recommendation 15, a Travel Rule implementation plan, and audited proof-of-reserves where relevant – move through EMI due diligence materially faster than those that rely on the FINMA registration alone. The licence opens the door. The compliance infrastructure keeps it open.

A second source of friction is geography. Many Swiss VASPs process transactions for customers across the EU/EEA and beyond. An EMI licensed in, say, Lithuania under the MiCA transitional regime, or in Malta under the MFSA framework, will ask not only about the VASP's Swiss regulatory status but also about the jurisdictions from which its end customers originate. A VASP with material transaction flow from higher-risk markets faces a longer, more document-intensive onboarding regardless of the strength of its Swiss compliance posture.

The FINMA Regime: What EMIs Actually Review

An EMI onboarding a Swiss VASP will treat the FINMA regulatory file as its primary risk-assessment document, so understanding what that file must contain is the first practical step. Under the FINMA regime, a business handling digital assets may require a fintech licence, a banking licence, or – at minimum – affiliation with a recognised self-regulatory organisation (SRO) for AML/CFT compliance purposes. The category that applies depends on the activities conducted: custody, exchange, issuance, or payment transmission.

Each of these categories creates a different document set. A fintech licence holder under the FINMA framework has accepted capital adequacy requirements, organisational standards, and ongoing supervisory reporting obligations. An SRO-affiliated entity has a lighter structural footprint but must demonstrate robust transaction-monitoring and customer due-diligence procedures consistent with FINMA guidance. EMIs with MiCA or EU-national AML obligations typically require evidence of whichever FINMA-recognised status applies, together with the SRO membership certificate or the FINMA licence number.

Operators we advise routinely underestimate how granular an EMI's compliance questionnaire becomes at the corporate-governance layer. Beneficial ownership – including any natural person holding a qualifying interest – must be identified to the same standard applied to the VASP's own customers. For a VASP with a complex holding structure, perhaps a Swiss operating entity beneath a BVI holding company or a Cayman fund vehicle, each layer requires clean documentation before the EMI's compliance committee will sign off.

There is also a currency dimension. Swiss-franc-denominated accounts are available from a handful of cantonal and private banks that have developed digital-asset policies. Euro-denominated accounts are more commonly provided by EU-based EMIs passporting into Switzerland or accepting Swiss VASPs as remote clients under their home licence. The legal basis for each differs, and the compliance expectations attached to each relationship differ accordingly.

For a scoped assessment of your FINMA regulatory file and its presentation to an EMI, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your entity structure, user base and transaction profile change the analysis, often materially.

What Does EMI Onboarding Actually Require from a VASP?

EMI onboarding for a VASP is a structured due-diligence process, not a simple account application. At its core, the EMI must satisfy its own regulator that the VASP customer meets the same AML/CFT standard the EMI applies to any high-risk business client. In practice, this means assembling a file that covers five distinct areas.

First, corporate documentation: certificate of incorporation, current constitutional documents, register of directors, beneficial ownership register and – for Swiss entities – extract from the Commercial Register (Handelsregisterauszug). For multi-entity structures, documentation is needed at every level of the holding chain.

Second, regulatory status: the FINMA licence, SRO certificate, or registration confirmation, together with any conditions attached to that status. If the VASP is in a transitional period – for instance, operating under interim measures while a full licence application is pending – the EMI will want a copy of the relevant FINMA correspondence confirming the transitional position is valid.

Third, AML/CFT policy documentation: the full AML policy, the customer risk-assessment methodology, a sample KYC pack (anonymised), the appointed Money Laundering Reporting Officer's credentials, and evidence of staff training. The Travel Rule (the obligation to pass originator and beneficiary data with virtual asset transfers) must be addressed explicitly: the EMI needs to know which Travel Rule solution the VASP uses and whether it covers all the transfer corridors the account will service.

Fourth, business model and transaction profile: a written description of the VASP's business model, the expected transaction volumes and values in the first twelve months, the source-of-funds profile for the VASP's customer base, and the geographies from which customers originate. This is not a formality – EMIs use this data to calibrate their own transaction-monitoring rules for the account.

Fifth, financial information: audited or reviewed financial statements, a current management accounts pack, and – where the VASP handles client funds – evidence of segregation and safeguarding arrangements consistent with applicable requirements.

In our cross-border practice, we have seen onboarding timelines range from a matter of weeks where the file is complete and the VASP's risk profile aligns with the EMI's existing book, to several months where additional information rounds are required or where the VASP's compliance infrastructure needs strengthening before the EMI will proceed. The variable is almost always documentation quality, not the underlying business.

How Does Swiss Law Interact with EU EMI Regulation?

Switzerland is not a member of the EU/EEA, so a Swiss VASP seeking an account with an EU-regulated EMI is treated as a third-country business client. This has two material consequences.

First, the MiCA (Markets in Crypto-Assets Regulation) regime – which governs CASP (Crypto-Asset Service Provider) authorisation and passporting across EU/EEA member states – does not extend to Switzerland. A Swiss-licensed VASP cannot rely on MiCA authorisation to access EU payment infrastructure; it must instead satisfy the EU EMI's own third-country due-diligence requirements. Those requirements are set internally by the EMI, subject to the AML/CFT rules of its home member-state regulator (for example, ESMA guidance where relevant, or the national competent authority under the applicable EU AML directive).

Second, the EU's regulatory environment for crypto businesses is converging around the CASP authorisation model. An EU-based EMI onboarding a Swiss VASP will increasingly ask whether the VASP's compliance programme is MiCA-equivalent in substance, even though it cannot be MiCA-authorised in form. In practical terms, this means the VASP's AML/CFT policies, governance standards, and customer-asset safeguarding arrangements should be benchmarked against MiCA expectations as a matter of commercial necessity, irrespective of the Swiss law obligations that formally apply.

For a Swiss VASP that also holds or is applying for a licence in an EU member state – for example, a CASP licence in Lithuania under MiCA, or a VFA licence in Malta under the MFSA regime – the picture is different. The EU licence can serve as the primary reference point for the EMI's due diligence, with the Swiss operation treated as a regulated branch or affiliate. This dual-jurisdiction structure is one that we regularly assist clients in mapping before they commit to a banking strategy.

There is also a tax interaction that affects the banking relationship. Swiss VAT treatment of digital-asset services, and the Swiss withholding tax regime as it applies to income generated through EMI-held accounts, can affect the account structure preferred by the VASP's corporate tax advisers. The EMI itself is not involved in these decisions, but the account structure it permits – whether segregated client-money accounts are available, whether multi-currency accounts are possible, and what reporting it will provide for year-end tax filings – directly affects how the VASP organises its financial reporting.

Decision Matrix: Which VASP Profile Suits Which Banking Strategy?

Not every Swiss VASP needs the same banking arrangement. The right structure depends on the business model, the transaction profile and the regulatory status.

A custody-only VASP – one that holds digital assets on behalf of clients but does not exchange or transmit fiat – typically needs a more limited banking relationship: an operating account for fee income and a safeguarding account for client fiat balances held incidentally. The AML burden is lower, and EMIs with standard corporate banking capabilities can often accommodate this profile without specialist crypto policy. The timeline to onboarding, where the VASP's SRO or FINMA status is clear, is typically shorter than for an exchange operator.

An exchange or broker VASP with retail or institutional client flows presents a different profile. High transaction volumes, fiat-to-crypto conversion flows, and a diverse customer geography all increase the EMI's compliance scrutiny. This profile requires an EMI with an established digital-asset policy, dedicated compliance resource, and a transaction-monitoring infrastructure capable of handling the volume. EU-based EMIs with MFSA or Bank of Lithuania authorisation, and with an existing digital-asset client book, are the natural counterparties. The onboarding process is more intensive, and the VASP should expect to negotiate account terms – including volume caps, settlement timelines, and the conditions for account review – as part of the commercial negotiation rather than accepting standard terms.

A token-issuer VASP, particularly one that has conducted a public offering or manages an ongoing secondary market, faces the most complex due diligence. The EMI will want to understand the token's legal classification under the FINMA taxonomy, the proceeds management structure for any issuance, and the on-going relationship between the token issuer, investors, and the fiat account. A formal legal opinion on token classification – under the FINMA regime and, where relevant, under MiCA – is a practical prerequisite for this onboarding category.

If a prior application stalled or an account was closed, a structured second read of your compliance file often surfaces the reason and the route forward. Write to OBOLUS at info@oboluslaw.com before the next attempt.

A Common Assumption: One Offshore Licence Is Enough

A common assumption among early-stage Swiss VASPs is that a single offshore registration – a BVI VASP Act registration or a Cayman CIMA filing – is sufficient to support a banking relationship with a European EMI. In our experience, this assumption causes preventable delays and, in some cases, account closures.

EU-regulated EMIs operating under MiCA or its transitional equivalents are subject to their own regulators' expectations about the quality of third-country clients' regulatory status. An offshore registration in a jurisdiction where supervision is light – even where the registration is technically valid – does not meet the threshold that a Bank of Lithuania-supervised or MFSA-supervised EMI applies to a crypto business client. The EMI's compliance committee will require evidence of substantive regulatory oversight, not merely formal registration.

The solution is not necessarily a full MiCA CASP authorisation. In many cases, a Swiss FINMA-regulated status, properly documented and presented, satisfies the EMI's threshold. Where it does not, a supplementary authorisation in a recognised EU jurisdiction – typically Lithuania or Malta for speed of process – provides the additional comfort the EMI needs. The key is to understand the EMI's requirements before designing the corporate structure, not after.

Regulators in the leading hubs increasingly expect VASPs to hold the licence appropriate to their activities and the jurisdictions of their customers, not merely the licence that was easiest to obtain. EMIs, regulated by those same authorities or their equivalents, reflect that expectation in their onboarding decisions.

In Practice: Stabilising Fiat Rails After an Account Closure

In a recent engagement, a digital-asset exchange holding a FINMA-recognised SRO affiliation had its primary EMI account closed following a portfolio-wide de-risking review by the EMI's parent group. The closure was not triggered by any compliance finding – the VASP had no regulatory action pending – but by a commercial policy change affecting all crypto-sector clients in the EMI's book.

We were engaged at short notice to review the VASP's compliance documentation, identify the gaps that were likely to cause difficulty in a reapplication, and prepare a presentation package for three alternative EMIs with established digital-asset policies. Two gaps were material: the Travel Rule implementation was documented but not tested against the VASP's actual transfer corridors, and the source-of-funds documentation for high-value customers was inconsistent in depth. Both were remediated before the new applications were submitted.

Within a matter of weeks of submission, two of the three EMIs advanced to a commercial terms discussion. The VASP's operational continuity was maintained through a temporary sub-account arrangement with an allied-jurisdiction banking partner while the primary relationship was being established. The outcome demonstrated that a well-structured reapplication, supported by a remediated compliance file, can move quickly even after a forced closure – provided the underlying regulatory status is sound.

Self-Assessment Checklist for Swiss VASP EMI Readiness

Before approaching an EMI, a Swiss VASP should be able to confirm the following without qualification.

On regulatory status: the FINMA licence, SRO certificate, or interim confirmation is current, unrestricted, and covers all activities for which the account will be used. Any conditions attached to the regulatory status are documented and the VASP is in compliance with each.

On corporate structure: the full ownership chain is documented to the level of the ultimate beneficial owner. Any nominee arrangements are disclosed. Any recent structural changes – mergers, disposals, changes of director – are reflected in current corporate documents.

On AML/CFT: the AML policy is current, approved by the board or equivalent governing body, and reflects the VASP's current business model. The MLRO is named and qualified. The Travel Rule solution is identified, implemented, and covers all material transfer corridors. Staff training records are available.

On transaction profile: the business plan includes a twelve-month transaction volume and value forecast, broken down by product line and customer geography. Source-of-funds documentation for high-value clients is consistent and complete.

On financial position: current financial statements – audited where available, reviewed where not – are available. Client funds are segregated from operating funds, and the safeguarding method is documented.

A VASP that can confirm all of the above is in a position to approach an EMI with a realistic prospect of onboarding within a commercial timeframe. A VASP that cannot confirm one or more of these points should address the gap before the application, not during it.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks and EMIs close crypto company accounts primarily for commercial rather than legal reasons: portfolio-wide de-risking decisions, group-level policy changes, or a specific assessment that the account's transaction profile exceeds the institution's risk appetite. Regulatory pressure on financial institutions to manage exposure to high-risk sectors also plays a role. A strong FINMA-regulated status and a well-documented compliance programme reduce – but do not eliminate – this risk. Structural diversification across more than one banking relationship is the most effective mitigation.

How can a VASP onboard with an EMI?

A VASP onboards with an EMI by submitting a complete due-diligence file covering corporate documentation, regulatory status, AML/CFT policies (including a Travel Rule implementation), a transaction profile forecast, and current financial information. The EMI will assess the file against its own compliance standards and its home regulator's expectations. In Switzerland, presenting a FINMA licence or SRO certificate as the primary regulatory reference typically satisfies the threshold for EU-regulated EMIs that have an established digital-asset policy, provided the rest of the file is complete.

What does client-money safeguarding require?

Client-money safeguarding requires that funds belonging to customers are held separately from the VASP's own operating funds, in an account or accounts clearly designated as holding client assets, with documentation demonstrating the segregation arrangement. Under most EMI and payment institution frameworks applicable across Europe, the safeguarding method – whether pooled safeguarding with a credit institution, insurance, or comparable guarantee – must be identified in the VASP's policies and communicated to the EMI as part of onboarding. The specific requirements vary by jurisdiction and licence category.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than seventy jurisdictions, on disputes and on-chain asset recovery across more than twenty-five forums, and on the banking, tax and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, banking and compliance stack across operating, custody and payment layers before clients commit – and we advise crypto exchanges, custodians, token issuers and funds across every major licensing hub. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in FINMA regulatory status, cross-border VASP compliance programmes, and EMI onboarding documentation for Swiss and EU-regulated digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours