EST · MMXXVI
Home/Jurisdictions/United States/Client funds safeguarding in United States (federal + state MTL)
Banking, Payments & EMI Onboarding

Client funds safeguarding in United States (federal + state MTL)

Client funds safeguarding in United States (federal + state MTL). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. T

A digital-asset payments company preparing to serve US customers often asks the same question: which rule governs the money sitting in our accounts between receipt and settlement? The answer cuts across two distinct layers. At the federal level, FinCEN (the Financial Crimes Enforcement Network) regulates money-services businesses under the Bank Secrecy Act. At the state level, every jurisdiction in which the company does business may require a separate money transmitter licence (MTL) – and each of those licences carries its own safeguarding standard for client funds.

Getting this wrong is not a theoretical risk. Operators in our practice have seen payment rails frozen after a single state examination revealed unlicensed activity. The cost of remediation – legal, reputational and operational – routinely exceeds the cost of building the right structure from the outset.

This page maps the safeguarding regime that applies to crypto-adjacent payments businesses operating under US federal and state MTL requirements, sets out the cross-border dimensions an inbound operator must address, and explains where counsel adds most value before the rails are committed.

What does the US safeguarding regime actually require?

US client-funds safeguarding is not a single federal rule – it is a layered obligation built from the federal Bank Secrecy Act framework administered by FinCEN, overlaid by state MTL statutes that impose their own permissible-investment and surety-bond requirements. A licensed money transmitter must hold client funds – whether fiat or, in some states, virtual currency – in a form and at a ratio set by state law. The required instruments typically include government securities, FDIC-insured deposit accounts, and similar low-risk assets. The specifics vary materially by state: what satisfies New York's NYDFS BitLicense and Money Transmitter regulations differs from the permissible-investment schedule in Texas, California or Wyoming.

The common thread is this: client money must be segregated from operating funds. That principle, which mirrors the safeguarding approach in EU and UK regimes, is embedded in every state MTL statute we have reviewed. Commingling – the practice of pooling client funds with working capital – is the most common trigger for enforcement action at the state level.

For digital-asset businesses specifically, the safeguarding question extends further. When the underlying asset is a stablecoin or a virtual currency rather than fiat, the operator must satisfy both the FinCEN registration requirement for money-services businesses and, where the state has defined virtual currency as money, the state MTL requirement as well. Several states – including New York, California, and Texas – have made that definitional move. Others have not. An operator that maps its user base without mapping the state-by-state definitional perimeter is building on an incomplete foundation.

How do federal and state obligations interact?

Federal registration with FinCEN is the floor, not the ceiling. FinCEN registration as a money-services business establishes AML/CFT program obligations – including the Travel Rule (the obligation to pass originator and beneficiary data with transfers above the applicable threshold) – but it does not licence the business to transmit money in any state. That permission is a state-by-state grant.

This two-layer architecture creates a sequencing problem for inbound operators. A company that registers with FinCEN and begins serving US customers without the relevant state MTLs has satisfied one federal obligation while potentially committing unlicensed activity across dozens of jurisdictions simultaneously. State attorneys general and state banking departments have demonstrated willingness to pursue exactly that scenario.

The practical consequence is that a US market-entry strategy for a payments or crypto-payments business must treat federal and state compliance as concurrent workstreams, not sequential ones. We regularly advise operators to build a state-priority matrix before committing to any banking or technology integration. That matrix ranks states by user concentration, by the risk of the state's MTL definition capturing virtual currency, and by the timeline and capital requirements for each application.

Operators we advise frequently underestimate the time dimension. State MTL applications are document-intensive and involve background investigations, surety bonds, permissible-investment evidence, and, in New York, an enhanced review under the NYDFS BitLicense regime. The combined federal-plus-priority-states programme typically takes a meaningful number of months; in our experience, operators who begin the process only after a banking partner requests compliance evidence are already behind.

What makes New York's BitLicense different?

The NYDFS BitLicense – administered by the New York Department of Financial Services – remains the most demanding single-state virtual-currency licence in the United States. It is a standalone authorisation, separate from New York's general money-transmitter licence, and it covers a broad set of virtual-currency business activities including transmission, custody, exchange and administration.

The safeguarding obligations under the BitLicense regime are explicit: licensees must maintain a surety bond or trust account in US dollars for the benefit of customers, hold virtual currency of the same type and amount as that owed to customers, and maintain a capital cushion that the NYDFS may adjust over time. These requirements sit above the general New York money-transmitter permissible-investment rules and apply concurrently where both licences are needed.

For an inbound operator, New York is often the first decision point. Serving New York customers without a BitLicense – even through an intermediary or a non-US entity – is an enforcement risk that regulators have pursued. The counterbalancing consideration is that a BitLicense, once obtained, signals a level of compliance maturity that banks and institutional counterparties in the US market actively value.

CTA #1 — Early-stage reader: The federal-plus-state matrix looks manageable in a spreadsheet and complex in practice. Your entity structure, your banking relationships and the states where your users actually sit all change the analysis significantly. To map your specific compliance perimeter before you commit to a US launch, contact OBOLUS at info@oboluslaw.com or map your options here.

How does the safeguarding regime apply to a non-US operator serving US clients?

A non-US operator serving US customers is not outside the state MTL perimeter merely because its entity is incorporated offshore. Several states apply their transmission statutes based on where the customer is located, not where the business is organised. An exchange or payments provider domiciled in the EU, UAE or Singapore that accepts US retail users is, in many states, conducting unlicensed money transmission unless it holds the relevant state MTL.

This is the point at which the single-offshore-licence assumption most consistently fails. A VASP operating under the MiCA CASP regime in the EU, or under VARA in Dubai, or under the MAS Payment Services Act in Singapore, holds authorisation that is not recognised or passported into the United States. Those licences satisfy the home-jurisdiction regulatory requirement; they do not satisfy the state-by-state obligation imposed by US law on any operator that reaches US persons.

The cross-border structuring question then becomes: does the operator geo-block US users, apply for the relevant state MTLs, or operate through a US-licensed partner under an agency or programme-management arrangement? Each path has a different capital, timeline and banking profile. In our cross-border practice, we see the geo-block approach used as a holding position during the licensing process – but it requires technically effective and legally defensible implementation, which is itself a compliance project.

Banking is the parallel constraint. US correspondent banks and payment processors conduct their own licensing diligence on counterparties. An operator that cannot demonstrate a coherent federal-plus-state compliance posture will find it difficult to maintain the fiat rails that make a US business viable. EMI onboarding – the process of securing a relationship with an electronic money institution that holds the fiat while the operator processes the crypto-side – does not resolve the state MTL question; it shifts the compliance burden to the EMI, which will contract around it through representations and indemnities.

What AML and Travel Rule obligations accompany the safeguarding requirement?

Every FinCEN-registered money-services business must operate a written AML/CFT program meeting the Bank Secrecy Act standard. For virtual-asset businesses, that program must address the particular risks of pseudonymous transactions, cross-chain activity, and mixing or privacy-enhancing protocols. The FinCEN guidance on convertible virtual currencies – including the concept of a VASP (virtual asset service provider) as defined in the FATF Recommendations – sets the doctrinal baseline.

The Travel Rule applies in the United States through FinCEN's existing funds-transfer and transmittal-of-funds rules, extended by interpretive guidance to cover transactions in convertible virtual currencies. The obligation to pass originator and beneficiary information along with a transfer applies above the applicable domestic threshold. State-level AML obligations are generally consistent with the federal baseline, though some states have enacted additional reporting requirements.

For a safeguarding programme to be defensible, the AML controls must be integrated with the funds-flow architecture. That means knowing, at the wallet level, whether a given balance is client money or firm money. Operators that treat AML compliance and funds safeguarding as separate workstreams consistently create the gaps that examinations surface. We have seen both issues appear together in state examination findings, and they are rarely coincidental.

A practical illustration

Earlier this year, a stablecoin payments company incorporated in a European jurisdiction sought to expand its US user base through a local marketing partner. The company held a CASP authorisation under an EU national regime and had FinCEN registration in place. It had not, however, applied for state MTLs in the four states that constituted the bulk of its intended customer base. We were engaged to assess the risk before the marketing campaign launched. The analysis identified that three of the four target states applied their money-transmission definitions to stablecoin transfers, and that the company's planned settlement flow would constitute unlicensed transmission in those states. The expansion was restructured: the US operation was channelled through a programme-management arrangement with a licensed US bank partner for the transition period, while state MTL applications were prepared in parallel. The marketing launch proceeded on a narrower geographic footprint and expanded as licences were obtained, avoiding an enforcement exposure that would have included potential per-transaction penalties under state law.

Why is banking the hardest part of the US safeguarding picture?

Regulatory compliance is a necessary condition for US banking access, not a sufficient one. A fully licensed money transmitter – one that holds MTLs in the relevant states, maintains its FinCEN registration, and operates a documented AML program – can still be de-risked by a bank on purely commercial grounds. The phenomenon of account closure without stated reason has been particularly acute for crypto-adjacent businesses in the US market.

The practical effect is that safeguarding compliance and banking access must be managed as a combined programme. An operator that structures its permissible-investment portfolio and surety-bond programme without first confirming that its banking relationships can sustain those holdings creates a structural vulnerability. We regularly advise clients to sequence their banking conversations before finalising the permissible-investment structure, because the two are interdependent: the bank must be willing to hold the safeguarding assets, report on them, and interface with state examination processes.

For inbound operators specifically, the choice of banking partner is often constrained by the operator's entity structure. A non-US parent with a US subsidiary faces a different bank-onboarding conversation than a purely domestic operator. The subsidiary's beneficial ownership disclosure, its AML programme documentation, and the parent's regulatory status in its home jurisdiction all become part of the bank's counterparty-risk assessment. Structuring the entity correctly – before the bank conversation begins – materially improves the onboarding outcome.

CTA #2 — Reader who has already hit a wall: If a prior bank application stalled or an account was closed, a second structural review can identify the friction point and the route back. A compliance posture that passed internal review often fails at the bank's correspondent-risk desk for a different, correctable reason. Write to OBOLUS at info@oboluslaw.com or map your options here to discuss a targeted review.

Which operator profile needs which US safeguarding structure?

The right safeguarding architecture depends on the operator's activity, user base and entity structure. The following decision branches reflect the principal profiles we encounter.

Profile A – Non-US exchange with material US retail exposure. This operator faces the fullest compliance burden: FinCEN registration, state MTLs in user-concentration states, a BitLicense if New York users are included, and an AML programme integrated with the state-level permissible-investment framework. The timeline from engagement to first-state-licence is typically measured in multiple months. The key risk is delayed banking: US banks will not open safeguarding accounts without evidence of the licence application at minimum, and many require a licence before account opening. A programme-management arrangement with a licensed US partner is usually the appropriate bridge.

Profile B – Stablecoin issuer or payments protocol with US market ambitions. This operator must first resolve the classification question – whether the issued instrument is a money transmission under federal and state law. Where it is, the safeguarding obligations are equivalent to Profile A. Where the instrument is classified differently (for example, as a security under SEC oversight), the regime shifts materially. Getting the classification analysis right before the product is live is the central legal task. A misclassification in either direction creates a compliance gap.

Profile C – B2B payments operator with no direct US retail clients. This operator has a narrower compliance perimeter. The money-transmission analysis typically turns on whether the operator holds or transmits funds in its own name. A pure technology provider that does not touch client money may fall below the MTL threshold in many states. However, the definition of "receiving" or "controlling" funds varies by state, and a technology arrangement that is structured as agency in one state may be characterised as principal transmission in another. The analysis must be conducted state-by-state, not as a blanket federal question.

A common assumption about the US safeguarding perimeter

A common assumption among operators expanding from licensed EU or offshore bases is that geo-blocking US IP addresses satisfies the US regulatory requirement. It does not – at least not automatically. State banking examiners and federal regulators look at the substance of who is receiving the service, not merely at the technical access controls. An operator that geo-blocks but continues to service US persons who access the platform through a VPN, or that maintains US persons on legacy accounts, is not outside the state MTL perimeter. The geo-block must be technically effective, consistently enforced, and accompanied by contractual prohibitions on US-person use. Even then, operators should take legal advice on whether the specific fact pattern satisfies the applicable state exemptions. This is an area where the gap between what operators believe and what regulators enforce is consistently larger than expected.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

US banks close crypto company accounts primarily for correspondent-risk and compliance reasons, rather than because the company has violated a rule. Banks assess the risk that their own AML programme will be implicated by a counterparty's transaction flow. A crypto business that cannot demonstrate a documented AML programme, clear source-of-funds controls, and a coherent licensing posture is categorised as high-risk regardless of its actual compliance record. Account closure often follows a periodic review rather than a specific incident. Improving the documented compliance posture before the next review cycle – and choosing a banking partner with an explicit digital-asset policy – is the standard remediation path.

How can a VASP onboard with an EMI?

A VASP (virtual asset service provider) seeking EMI onboarding must typically demonstrate its own regulatory status, its AML/KYC programme quality, its transaction monitoring capability, and the coherence of its licensing posture in the jurisdictions where it operates. The EMI conducts its own counterparty due diligence and will require documentation of the VASP's licence, its compliance policies, its beneficial ownership structure, and – increasingly – its Travel Rule implementation. For US-facing VASPs, the EMI will also want evidence of FinCEN registration and, where applicable, state MTLs. Structuring the application package before approach substantially improves the outcome and reduces the time to account opening.

What does client-money safeguarding require?

Under US state MTL regimes, client-money safeguarding requires: segregation of client funds from operating capital; investment of client balances in permissible instruments specified by state law (typically government securities or FDIC-insured deposits); maintenance of a surety bond or equivalent at a level set by the state; and ongoing reconciliation to confirm that client-money holdings match client-money liabilities at all times. In New York, the NYDFS BitLicense adds virtual-currency-specific requirements – including holding the same type and amount of virtual currency as owed to customers. The combined obligation is operationally demanding and requires treasury and compliance functions to work from a shared data set.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and payments operators on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the banking, tax and compliance structures that sit around them. We map the licence stack across operating, custody and payment layers before you commit – and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us via t.me/oboluslaw.

By Victor Olsen, Regulatory and Compliance Analyst – specialising in US federal and state money-transmission compliance for digital-asset businesses and cross-border VASP licensing programmes.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours