EST · MMXXVI
Home/Jurisdictions/United Kingdom/Client funds safeguarding in United Kingdom
Banking, Payments & EMI Onboarding

Client funds safeguarding in United Kingdom

Client funds safeguarding in United Kingdom. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Operating a digital-asset business in the United Kingdom without a clear client funds safeguarding structure is one of the fastest routes to regulatory scrutiny, frozen fiat rails, and lost banking relationships. The Payment Services Regulations and the Electronic Money Regulations – the two principal UK frameworks governing how firms hold client money – impose specific obligations on every payment institution and e-money institution that touches sterling on behalf of a customer. For a crypto business with a UK footprint, understanding those obligations before the first pound arrives is not optional: it is the foundation of the entire banking stack.

Client funds safeguarding in the United Kingdom means holding customer money in a designated safeguarding account at an authorised credit institution, or in qualifying liquid assets, kept separate from the firm's own funds and insulated from insolvency. The Financial Conduct Authority (FCA) supervises compliance directly and expects documented, tested procedures – not a policy paragraph buried in a compliance manual.

This page explains who is caught, what the regime requires, how an inbound digital-asset business structures its safeguarding approach, and where cross-border complexity concentrates.

Who must safeguard client funds in the UK?

Any firm authorised or registered as a payment institution or e-money institution under the FCA's supervisory remit must safeguard relevant funds. The obligation attaches the moment a firm receives funds from a payment service user in exchange for a payment transaction or e-money issuance. For a crypto business, that moment typically arrives at the fiat-on-ramp: when a user sends sterling to buy tokens, or when a payment facilitator holds settlement balances awaiting execution.

The FCA distinguishes between authorised payment institutions (APIs), small payment institutions (SPIs), authorised electronic money institutions (AEMIs), and small electronic money institutions (SEMIs). Safeguarding obligations apply most extensively to APIs and AEMIs. SPIs and SEMIs operate under lighter-touch registration but face significant volume caps – and in our practice we see operators routinely underestimate how quickly those caps are breached once a product scales.

A crypto exchange that processes sterling deposits and withdrawals, a custodian that holds fiat alongside digital assets, and a stablecoin issuer that takes GBP against token issuance are all potentially within the perimeter. The label the business applies to itself does not determine regulatory status: the FCA looks to the substance of the activity. A firm calling itself a "technology provider" but settling sterling balances on behalf of users is providing payment services and must hold the correct authorisation.

The FCA registration for cryptoasset businesses under the Money Laundering Regulations (MLR) is a separate, parallel obligation. MLR registration addresses anti-money-laundering supervision; it does not substitute for payment services or e-money authorisation, and it confers no safeguarding framework. We regularly advise businesses that mistakenly treat MLR registration as a general licence to operate. It is not.

CTA #1 – For the reader meeting the safeguarding perimeter question for the first time: The standard analysis above describes the regulatory perimeter in general terms. The precise position depends on your entity structure, user flows and the jurisdictions your customers sit in. For a scoped assessment of where your business falls, contact OBOLUS at info@oboluslaw.com.

What does the UK safeguarding regime actually require?

UK safeguarding rules demand that relevant funds – those received from payment service users and not yet transmitted – be either placed in a designated safeguarding account at an authorised credit institution or invested in secure, liquid, low-risk assets. The account must be labelled clearly as a safeguarding account, must not be commingled with the firm's own operating funds, and must be reconciled daily.

The FCA's guidance on safeguarding, updated periodically, goes further than the baseline. Firms are expected to maintain a safeguarding policy document, perform regular internal audits of the safeguarding process, keep records sufficient to allow reconstruction of all held funds at any given moment, and produce those records on demand. An annual safeguarding audit – carried out by the firm's external auditor – has become a de-facto expectation for all but the smallest authorised firms.

Insurance is available as a partial alternative to the segregated-account method, but in our practice almost every digital-asset firm we advise uses the credit-institution account route. The insurance route carries its own conditions, and insurers have tightened underwriting for crypto-adjacent firms considerably. The practical answer, for most inbound businesses, is a dedicated sterling safeguarding account with a bank or EMI (electronic money institution) that already has a working crypto compliance policy.

That last point is where the complexity concentrates. Most UK high-street banks remain cautious about opening safeguarding accounts for crypto companies, even FCA-registered ones. The firms that succeed are those that present a complete compliance package at first engagement: a clear business model narrative, an AML/KYC policy aligned to FCA expectations, a named MLRO, source-of-funds documentation, and evidence of the firm's own KYC controls over its customers. A safeguarding account application that arrives without these materials will typically fail – not because the business is non-compliant, but because the bank has no basis on which to assess it.

How does UK safeguarding apply to a VASP or crypto exchange?

A VASP (virtual asset service provider) operating in the UK that handles client fiat sits squarely within the safeguarding perimeter when it holds sterling on behalf of users between the point of receipt and the point of execution. This covers the float period on a crypto exchange – the interval between a user depositing GBP and that GBP being converted into a digital asset. Many operators assume that because the ultimate product is a token, no payment services framework applies. That assumption is incorrect.

The VASP and the payment services frameworks interact. FCA MLR registration is required for crypto businesses conducting exchange, custody, or transfer activity in or into the UK. Where those businesses also hold fiat, API or AEMI authorisation is required on top. The two regimes run in parallel, and the FCA expects the firm to manage both compliance programmes simultaneously – including separate record-keeping obligations under each.

In practice, we see three common structural responses. First, the operating-entity model: the UK-registered entity is an API or AEMI, holds the safeguarding accounts, and passes fiat to an affiliate for digital-asset execution. Second, the partner-EMI model: the crypto firm does not itself hold a payment services licence and instead relies on an FCA-authorised EMI to issue e-money and safeguard fiat on its behalf, under a written agreement. Third, the offshore-entity model: a non-UK entity holds the payment licence, and the UK entity provides only technology or marketing services without directly handling sterling.

Each model carries a different risk and cost profile. The operating-entity model gives the business the most control but requires the firm to pass FCA authorisation, meet capital adequacy requirements, and maintain ongoing compliance infrastructure. The partner-EMI model is faster to market but creates dependency on a third party's risk appetite for crypto – and that appetite can change. The offshore model works only where the UK entity genuinely does not carry on regulated payment activities in the UK; any UK user-facing activity that involves sterling handling will likely pull the UK entity back into the perimeter regardless of where the licence sits.

In a recent matter, a payments company operating across the UK and an EU member state structured its safeguarding through a partner EMI and relied on that relationship as its primary fiat infrastructure. When the EMI revised its crypto policy following a regulatory consultation, the payments company lost access to its safeguarding accounts with short notice. We worked with the firm to identify a second EMI relationship and to re-architect the flow so that no single counterparty held the entire sterling float. The disruption was contained, and the business maintained continuity throughout. The lesson is structural: single points of failure in fiat infrastructure are an operational and regulatory risk, not merely a commercial inconvenience.

How does a crypto business onboard with a UK EMI?

EMI onboarding for a digital-asset business in the UK is a structured due-diligence process that typically takes from several weeks to a few months, depending on the complexity of the business model and the EMI's own capacity. The FCA-authorised EMI is itself subject to FCA supervision and is responsible for conducting its own AML/KYC assessment of every business customer it onboards – including crypto firms.

The process generally unfolds in four stages. In the first stage, the crypto firm prepares an onboarding pack: corporate documents, beneficial ownership information, an AML/KYC policy, a description of the business model and customer base, source-of-funds and source-of-wealth documentation, and the FCA MLR registration certificate where applicable. In the second stage, the EMI's compliance team reviews the pack and raises queries. For crypto firms, those queries typically focus on the firm's own KYC process, its transaction monitoring controls, and the jurisdictions from which its customers are drawn.

In the third stage, the EMI may require an in-person or video call with the firm's MLRO and, in some cases, a site visit or a review of the firm's compliance infrastructure by a third-party auditor appointed by the EMI. In the fourth stage, terms are agreed and an account is opened. The EMI will typically impose transaction limits, periodic re-review obligations, and ongoing reporting requirements as conditions of the relationship.

The firms that complete EMI onboarding fastest are those that present the process as a compliance narrative rather than a document dump. The EMI is asking a single underlying question: can it be confident that this business will not create regulatory or reputational risk? A firm that can answer that question clearly – through the quality and completeness of its documentation, and through the evident maturity of its compliance programme – will move through the queue quickly. A firm that submits bare corporate documents and a template AML policy will wait longer, or fail entirely.

What are the cross-border complications for UK safeguarding?

Most digital-asset businesses operating in the UK do not serve only UK customers. They serve customers in the EU, in the Gulf, in Southeast Asia, and in jurisdictions where the local regulatory status of the activity ranges from clearly licensed to formally unaddressed. That multi-jurisdictional user base creates layered safeguarding complexity that a purely UK-centric analysis misses.

Under MiCA – the EU's Markets in Crypto-Assets Regulation, supervised by ESMA and national competent authorities – a UK-registered VASP serving EU customers may need a parallel EU authorisation as a CASP (crypto-asset service provider). MiCA does not provide for passporting from third countries. A UK entity serving EU retail customers at scale will likely need either an EU-authorised entity or a commercial relationship with an EU-licensed firm. The safeguarding requirements under MiCA for CASPs handling client funds broadly mirror the UK model – segregation, designated accounts, documented procedures – but the specific capital and reserve thresholds are set separately under the EU framework and must be verified against current legislation.

The banking relationship also extends beyond borders. A UK API or AEMI holding safeguarding accounts denominated in currencies other than sterling needs correspondent banking relationships or multi-currency e-money accounts. Those relationships carry their own due-diligence cycles. A US-dollar account for a UK-registered crypto firm will face US Bank Secrecy Act-aligned scrutiny from any US correspondent bank, regardless of the UK regulatory standing of the firm.

The Travel Rule – the FATF Recommendation 15-aligned obligation to pass originator and beneficiary data with a virtual asset transfer – applies in the UK to VASPs above the applicable de-minimis threshold. UK Travel Rule compliance must interface with the Travel Rule regimes of the counterpart jurisdictions at both ends of the transfer. Where a UK VASP transacts with a VASP in a jurisdiction that has not yet implemented the Travel Rule, the UK firm must still meet its own obligation and document its approach to the unhosted wallet problem. We have seen this create friction with both banking partners and with payment processors that aggregate fiat flows across multiple asset types.

The cross-border interaction between UK safeguarding, EU MiCA obligations, and Travel Rule compliance is where the risk concentrates for a multi-market operator. Addressing each framework in isolation – one workstream for the FCA, a separate process for MiCA, a third process for Travel Rule – is inefficient and creates gaps. In our practice, we advise clients to map all three simultaneously, because the choices made in one layer constrain the options available in the others.

CTA #2 – For the reader who has already attempted onboarding or licensing and encountered difficulty: If a prior EMI application stalled or an existing banking relationship was closed, a structured second review can identify the structural reason and the route back. Write to us at info@oboluslaw.com to discuss.

What are the most common safeguarding mistakes in UK crypto businesses?

The most common mistake is conflating MLR registration with a licence to hold client money. FCA MLR registration for a cryptoasset business confirms that the firm meets the FCA's AML/CFT supervision standards for its crypto activity. It does not authorise the firm to hold sterling on behalf of clients under the payment services framework. A firm that collects fiat from users and holds it, even briefly, without an API or AEMI authorisation – or without a licensed partner that holds it on its behalf – is operating outside the perimeter. Enforcement risk and account closure follow from there.

The second common mistake is treating safeguarding as a static obligation. The FCA expects ongoing compliance: daily reconciliations, periodic audits, prompt notification of safeguarding failures, and updated policies when business models change. Firms that pass their initial authorisation and then let the safeguarding infrastructure age without review are systematically exposed when the FCA conducts its next supervisory engagement or when a banking partner triggers a review.

A third mistake is relying on a single EMI or banking relationship without a tested alternative. The crypto sector has experienced a number of abrupt account closures – sometimes with very limited notice – when banking partners revise their crypto risk appetite. A business whose entire fiat operation runs through one EMI and whose safeguarding accounts sit entirely at one bank is one policy change away from operational failure. Building a second relationship in parallel, even at lower volume, is operational risk management, not overhead.

A common assumption in the market is that a single offshore licence – an EU CASP authorisation, a VARA licence from Dubai, or a Singapore DPT licence from the Monetary Authority of Singapore (MAS) – is sufficient to serve UK customers legally. It is not. The FCA's territorial reach is based on where customers are located, not merely where the firm is incorporated. A business incorporated offshore but actively marketing to and serving UK clients may be conducting regulated activity in the UK. The correct structure is almost always an entity that holds the appropriate UK authorisation, or at minimum a carefully documented business model that keeps genuinely UK-facing activity within a licensed perimeter.

Self-assessment: does your safeguarding structure hold?

A well-structured UK safeguarding position answers yes to each of the following questions. Does the firm hold FCA authorisation or registration appropriate to its activities – both under the payment services framework and under the MLR, where applicable? Are relevant funds held in a designated safeguarding account at an FCA-authorised credit institution, clearly labelled and segregated from operating funds? Is a daily reconciliation performed and documented? Has the safeguarding policy been reviewed in the last twelve months, and does it reflect the firm's current business model? Does the firm have a named MLRO with adequate seniority and resource? Does the firm have at least one tested alternative for its fiat banking relationship? And does the firm understand its Travel Rule obligations in the UK and in the jurisdictions of its counterpart VASPs?

If any of those answers is uncertain or negative, the safeguarding structure carries risk. The FCA does not penalise firms for honest gaps identified and remediated through internal process. It does penalise firms that should have identified gaps and did not.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily when the firm cannot demonstrate adequate AML/KYC controls, when the transaction profile does not match the stated business model, or when the bank revises its internal risk appetite for the sector. FCA MLR registration reduces – but does not eliminate – this risk. Banks conduct their own customer due-diligence cycle independently of the FCA, and a firm whose compliance documentation is incomplete or out of date remains vulnerable regardless of its regulatory status.

How can a VASP onboard with an EMI?

A VASP seeking EMI onboarding in the UK should prepare a complete compliance package: corporate structure, beneficial ownership chain, AML/KYC and transaction-monitoring policies, FCA MLR registration evidence, a clear business model narrative, and source-of-funds documentation. The EMI will conduct its own due-diligence review, which may include a call with the MLRO and periodic re-review conditions. The process typically takes several weeks to a few months. Firms with a documented, well-governed compliance programme move through the process significantly faster than those presenting minimal documentation.

What does client-money safeguarding require?

Under the UK payment services and e-money frameworks, safeguarding requires that relevant funds be held in a designated account at an authorised credit institution, segregated from the firm's own money, reconciled daily, and covered by a documented safeguarding policy. The FCA expects annual audits of the safeguarding process and may require the firm to demonstrate its reconciliation and record-keeping procedures on supervisory inspection. Commingling client funds with operating funds is a fundamental breach that carries significant enforcement consequences.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – structuring licensing, banking and tax as one mandate rather than three disconnected workstreams. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in FCA-supervised payment services and cryptoasset registration frameworks for cross-border digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours