EST · MMXXVI
Home/Jurisdictions/United Kingdom/Correspondent banking access in United Kingdom
Banking, Payments & EMI Onboarding

Correspondent banking access in United Kingdom

Correspondent banking access in United Kingdom. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Correspondent banking access in the United Kingdom sits at the intersection of regulatory registration, de-risking pressure and cross-border payment architecture. For a digital-asset business – whether an exchange, a custodian or a VASP (virtual asset service provider) – the question is rarely whether the UK is the right commercial home. The question is whether you have the legal and compliance posture to hold fiat rails there long enough to build. The Financial Conduct Authority (FCA) sets the registration threshold; the correspondent banks set a second, informal one. Satisfying both at the same time requires a structured approach – and the cost of getting it wrong is a frozen payment account and a broken product.

Why Correspondent Banking Matters for Digital-Asset Businesses in the UK

Correspondent banking is the backbone of fiat settlement for every digital-asset business that touches sterling or cross-border payments. A correspondent bank (an institution that holds nostro accounts on behalf of another bank or payment institution) provides the clearing infrastructure that lets a crypto exchange receive client deposits, process withdrawals and settle with counterparties. Without it, a licence is commercially inert.

The UK market is materially harder to access than it was several years ago. A broad programme of de-risking – driven by regulatory pressure on UK-clearing banks and heightened AML scrutiny – has led many Tier 1 correspondent banks to exit relationships with crypto businesses or impose conditions that are difficult to meet without a demonstrable compliance programme. In our practice, we see newly registered businesses underestimate this second gate. The FCA registration is necessary; the correspondent bank onboarding is the real test.

De-risking is not uniform. Some clearing institutions maintain managed exposure to FCA-registered VASPs, particularly those with strong transaction-monitoring programmes, clear customer-type restrictions and documented governance. The gap between the banks that have exited the sector and those that remain is almost entirely a compliance-posture question, not a categorical business-type exclusion.

The FCA's cryptoasset registration under the Money Laundering Regulations is the legal prerequisite for operating as a VASP in the UK. Without it, a business cannot lawfully provide cryptoasset exchange or custody services to UK customers, and no compliant correspondent bank will open an account.

The FCA Registration Baseline: What It Covers and What It Does Not

FCA registration under the Money Laundering Regulations (MLR) is the current UK VASP authorisation path; it is an AML-focused threshold, not a full prudential licence. Registration confirms that the FCA has assessed the business's AML/CFT systems, beneficial ownership and management fitness. It does not confer an e-money or payment institution licence, and it does not authorise regulated financial promotion without further steps.

The FCA has taken a restrictive approach to MLR registration. The regulator has refused or returned a material proportion of applications on grounds including inadequate AML controls, unclear governance and unresolved management fitness concerns. Businesses should treat the application as substantive, not administrative.

The FCA also administers the UK financial-promotion regime for cryptoassets, which imposes separate obligations on firms communicating investment content to UK persons. A VASP registered under the MLR still requires either its own FCA authorisation or the involvement of an FCA-authorised approver to communicate financial promotions lawfully. Correspondent banks and EMI partners increasingly review promotion compliance as part of their own onboarding due diligence.

Separately, a business that holds client money or processes payments in the UK may also need registration or authorisation under the Payment Services Regulations, as a payment institution (PI) or electronic money institution (EMI). These are substantive prudential regimes with capital requirements, safeguarding obligations and conduct rules. The interaction between the MLR registration and PI/EMI authorisation is a common structural mistake: operators assume one covers the other. It does not.

For the cross-border business, the UK's departure from the EU means there is no passporting. An FCA registration or authorisation carries no automatic recognition in EU member states. A business serving both UK and EU customers needs separate regulatory footing on each side of the Channel.

To map the licensing layers for your UK entity before you submit, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the customer base, the payment flows – change the analysis.

What Do Correspondent Banks Actually Require from a Crypto Business?

Correspondent bank onboarding for a digital-asset business in the UK follows a more demanding due-diligence path than for a conventional payments business. The threshold questions are largely consistent across institutions, even if the specific documentary requirements vary.

The first filter is regulatory status. A VASP without FCA MLR registration will not proceed past an initial enquiry at any compliant UK correspondent. Registration is a floor, not a differentiator. The banks that remain active in the sector are differentiated by the complexity of the crypto business they will accept: some handle spot exchange only; others extend to lending, staking and custody. The scope of your activities must match the risk appetite of your target institution.

The second filter is AML programme quality. Banks assess transaction monitoring architecture, customer risk classification, sanctions screening coverage and the quality of your MLRO (money laundering reporting officer). A nominal compliance function – a single named officer with no independent resource – will not satisfy a Tier 1 correspondent. Banks have become markedly more forensic about this since the FCA imposed requirements on them to undertake enhanced due diligence on VASP counterparties.

The third filter is business-model legibility. A correspondent bank's compliance team must be able to explain to its own regulator why it holds an account for your business. That requires a clear product description, a defined customer type, documented restrictions on high-risk geographies and a coherent AML narrative. Businesses that combine multiple activity types – exchange, custody, lending, DeFi aggregation – in a single entity present a more complex narrative and face longer onboarding timelines.

In practice, the onboarding timeline at a UK correspondent bank varies from several weeks to several months, depending on the institution's appetite and the state of your documentation at first submission. Submitting a complete package at the outset – rather than responding reactively to information requests – materially shortens the process.

EMI Onboarding as an Alternative Fiat Rail

Where a direct correspondent bank relationship is unavailable or impractical, onboarding with a UK or EU electronic money institution provides an alternative fiat rail. An EMI holds authorisation to issue e-money, operate payment accounts and, in many cases, process cross-border transfers. For a VASP that needs sterling settlement without a direct bank relationship, an EMI account can provide functional equivalence for many operating purposes.

The EMI onboarding process mirrors the correspondent bank process in structure, if not in formality. Regulated EMIs have their own AML obligations and will conduct due diligence on the VASP's regulatory status, beneficial ownership, business model and compliance programme. The documentation required is materially similar; the primary difference is that some EMIs have built specialist onboarding tracks for FCA-registered VASPs, reducing the review time.

The risk profile of an EMI relationship differs from a correspondent bank relationship in one important respect: client-money safeguarding. Under the UK Payment Services Regulations, EMIs are required to safeguard client funds – either by holding them in a segregated account at a credit institution, or by covering them with an insurance policy or guarantee. The safeguarding obligation protects the VASP's client funds against the EMI's insolvency, but it also means the EMI itself requires access to a banking relationship that supports segregated safeguarding. The chain of dependency on bank access runs all the way through the stack.

For cross-border businesses, EU-authorised EMIs continue to operate into the UK under temporary permissions or via local branches; UK-authorised EMIs cannot passport into the EU. A business that needs euro and sterling rails in parallel therefore needs to map the EMI landscape on both sides carefully.

In a recent banking-access matter, an FCA-registered exchange had its primary sterling account closed following a change in its correspondent bank's de-risking policy. We identified two compliant EMI paths, supported the client's documentation rebuild and coordinated the onboarding process across both relationships simultaneously. The client maintained uninterrupted fiat settlement while the primary banking relationship was re-established with a different institution. No client funds were at risk at any point.

The Travel Rule and AML Baseline: What Correspondent Banks Are Checking

The Travel Rule (the obligation, under FATF Recommendation 15 and its UK implementation, to transmit originator and beneficiary data alongside a virtual asset transfer) has become a practical due-diligence checkpoint in correspondent bank onboarding. A VASP that cannot demonstrate Travel Rule compliance – both outbound transmission and inbound verification – will face difficult questions from any institution applying current FATF standards.

UK implementation of the Travel Rule followed the FATF model, with the FCA as the supervising authority. A VASP subject to UK regulation must have documented processes for collecting, transmitting and receiving the required data, and must have a policy for handling transfers from non-compliant counterparties (sometimes called the "sunrise problem"). Correspondent banks increasingly ask for this documentation as part of their onboarding pack.

FATF Recommendation 15 on virtual assets and its UK implementation sit alongside the general AML/CFT obligations under the MLR. The two sets of requirements overlap but are not identical; a compliance programme that addresses one without the other will fail due diligence at a sophisticated counterparty.

Sanctions screening is a separate but related dimension. UK VASPs are subject to obligations under UK financial sanctions law, and correspondent banks will assess whether a VASP's screening programme covers the relevant designations – including those maintained by the Office of Financial Sanctions Implementation (OFSI). A programme that screens against US OFAC lists but not UK OFSI designations is a common gap, particularly for businesses that originally built their compliance stack for a US audience.

Cross-Border Structure and Tax Interaction: Where the UK Fits in the Stack

For an inbound digital-asset business – one incorporated outside the UK that wants to access UK payment rails – the structural question is whether to establish a UK entity with FCA registration, rely on a non-UK-licensed entity with an EMI relationship, or use a hybrid model. Each option carries different regulatory, tax and banking consequences.

A UK subsidiary with its own FCA registration provides the cleanest correspondent banking narrative but introduces UK corporation tax exposure, the UK substance requirements for any treaty benefits and the full weight of the FCA's AML supervision. It is the right choice for businesses with material UK customer volumes or UK-source revenue.

A non-UK entity relying on a UK-passported EMI (where the EMI holds UK authorisation and provides sterling services) avoids some of the regulatory build cost, but also limits the depth of relationship available with UK Tier 1 banks. It is a viable path for businesses with limited UK-customer exposure during an early growth phase.

The tax interaction is material. A UK branch or subsidiary that holds sterling balances and processes UK-source transactions may create a taxable presence even if the entity is managed from elsewhere. The interaction between VAT on crypto-related services, the income character of exchange fees and the treatment of staking rewards under UK tax law are each live questions that affect the total cost of the UK operating structure. These should be resolved before the banking relationship is opened, not after.

The cross-border dimension is also a banking narrative question. A UK entity that is wholly owned by a holding company in a jurisdiction perceived as high-risk for AML purposes will face elevated scrutiny from the correspondent bank, even if the UK entity itself has a clean compliance record. The group structure and the ultimate beneficial ownership chain must present coherently at every level of the stack.

If a prior UK banking application stalled or an account was closed, a structural review can surface the reason and the route back. Write to info@oboluslaw.com and we will assess the options.

Decision Matrix: Which Structure Fits Which Profile?

The right UK banking structure depends on the operator's profile, not a universal template. The following decision branches describe the principal options and their trade-offs.

Profile A – Exchange with material UK retail customer volumes: A UK subsidiary with FCA MLR registration and, where client money is held, PI or EMI authorisation is the appropriate structure. A direct correspondent bank relationship provides the most stable fiat rail for this volume. The onboarding timeline is the longest, but the regulatory narrative is the clearest and the relationship with the correspondent bank is most defensible over time.

Profile B – Cross-border exchange with limited UK customer exposure: An EU-authorised entity with a UK-accessible EMI relationship may be sufficient for an initial market-entry phase. The trade-off is lower relationship depth with UK Tier 1 banks and exposure to changes in the EMI's own banking arrangements. This profile should monitor its UK customer volumes: once they become material, the regulatory basis should be reviewed.

Profile C – Custodian or fund administrator needing sterling settlement for institutional clients: Institutional client types generally require a more robust demonstration of safeguarding arrangements and AML programme quality. A UK entity with FCA registration and a direct bank relationship is typically required. The correspondent bank's due diligence will focus heavily on the end-client onboarding standards and the technology used for asset segregation.

Profile D – Token issuer needing UK fiat rails for a fundraise or ongoing treasury management: The regulatory basis depends on whether the token is classified as a regulated financial instrument under UK law. If it is, the FCA authorisation requirement may extend beyond MLR registration. Banking access in this profile also turns on whether the issuer can provide a credible AML narrative for incoming funds at the token-sale stage, which requires early engagement with the prospective correspondent bank.

Common Mistakes – and How to Avoid Them

A common assumption among operators entering the UK is that FCA MLR registration automatically resolves the banking question. It does not. Registration removes the legal prohibition on operating; it does not compel any bank to provide services. The compliance posture that satisfies the FCA and the compliance posture that satisfies a Tier 1 correspondent bank overlap substantially but are not identical – and the banks' additional requirements, particularly around transaction monitoring architecture and product-scope legibility, must be planned for independently.

A second frequent mistake is submitting a banking application before the FCA registration is confirmed. Some correspondent banks will begin due diligence on a pre-registration basis; most will not progress to account opening until registration is on the public register. The sequencing between the regulatory and banking timelines should be mapped explicitly at the outset, including the risk that the FCA process takes longer than anticipated.

A third mistake is treating the UK banking relationship as isolated from the group structure. Correspondent banks conduct group-level AML assessments. A holding structure that routes through a jurisdiction flagged by FATF or a beneficial owner with unresolved regulatory history in another market will create problems at the UK entity level, regardless of how clean the UK entity's own compliance record is. We regularly advise clients to resolve group-level structural questions before engaging with UK banks, rather than discovering them mid-onboarding.

Finally, operators consistently underestimate the documentation burden of the onboarding process. A complete banking onboarding pack for a UK correspondent typically includes corporate structure charts, AML policies, a transaction-monitoring system description, MLRO CVs and fitness evidence, product descriptions for each client-facing service, sample customer risk assessments and evidence of FCA registration. Assembling this in a coherent, pre-reviewed format – rather than responding to sequential information requests – is among the most practical things an operator can do to accelerate the timeline.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts most commonly for three reasons: a failure to meet the bank's internal AML standards for the VASP sector, a change in the bank's de-risking policy that exits the asset class entirely, or a deterioration in the account's transaction profile – for example, unexplained volume spikes or connections to flagged counterparties. FCA registration is a prerequisite, but it does not prevent de-risking. A strong AML programme, a clearly defined business model and ongoing communication with the relationship manager are the practical defences. When closure occurs, the immediate priority is preserving client-fund access and identifying alternative rails.

How can a VASP onboard with an EMI?

A VASP onboards with a UK or EU EMI by providing substantially the same documentation required by a correspondent bank: FCA registration evidence, corporate structure, AML policies, MLRO details, a product description and a customer risk assessment. Some EMIs have built structured onboarding tracks for registered VASPs, reducing the review cycle. The critical due-diligence points are the VASP's regulatory status, its beneficial ownership transparency and its transaction-monitoring capability. Onboarding timelines vary by institution and by the complexity of the VASP's activity scope; preparing a complete, pre-reviewed pack at first submission is the most effective way to shorten the process.

What does client-money safeguarding require?

Under the UK Payment Services Regulations, a payment institution or EMI holding client funds must safeguard those funds by either placing them in a designated safeguarding account at a credit institution, or covering them under an insurance policy or comparable guarantee. The funds must be segregated from the firm's own money and identifiable at all times. The safeguarding obligation exists to protect clients if the institution becomes insolvent. For a VASP that holds client fiat balances through a PI or EMI structure, the safeguarding chain – from client account to the institution's own bank – must be confirmed and documented before the service is offered.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence stack across operating, custody and payment layers before you commit – so the structure is defensible when the banks and regulators examine it. To discuss your UK banking and payment access question, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP registration, AML programme design and correspondent banking access for digital-asset businesses across the UK and EU.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours