Operating a fiat on/off-ramp in the United States without the correct federal and state authorizations exposes a digital-asset business to enforcement by FinCEN, state banking departments, and potentially the SEC or CFTC — before a single wire is sent. The U.S. fiat rails question is, at its core, a layered licensing problem: federal registration under FinCEN as a money services business (MSB) sits beneath a patchwork of state money-transmitter licences (MTLs), each with its own surety bond, capital, and examination regime. Mapping that stack accurately — and then finding a bank or electronic money institution (EMI) willing to clear fiat through it — is the practical challenge that stalls more crypto launches than any other single issue.
This page sets out the regulated basis for fiat on/off-ramp activity in the U.S., the application process and its realistic demands, the cross-border interaction with banking and tax, and the decision points that determine whether a domestic structure, an inbound foreign arrangement, or a hybrid model best fits a given operator profile.
What activity triggers federal and state money-transmitter obligations?
Any business that accepts fiat currency and transmits value — whether to a crypto wallet, an exchange account, or a beneficiary in another state — is, at the federal level, a money services business subject to Bank Secrecy Act obligations administered by FinCEN under the applicable MSB provisions. That registration is mandatory before the business processes a single transaction. It does not, however, license the business to operate: it registers it for AML and suspicious-activity-reporting purposes only.
State-level licensing is the operational layer. Money-transmitter licence requirements vary materially across jurisdictions. Most U.S. states require a separate MTL from their banking department or department of financial institutions. A handful of states impose additional crypto-specific requirements — most notably the NYDFS BitLicense, which applies to virtual-currency business activity directed at New York residents regardless of where the operator is incorporated. A business accepting or transmitting fiat on behalf of users in multiple states must, in practice, hold licences across each of those states — a compliance posture that routinely demands a licence in most or all of the fifty states and the District of Columbia for a national-scope operation.
The threshold for "transmitting" is interpreted broadly. Holding customer fiat pending a crypto purchase, netting positions, or simply routing a wire through a pooled account can each bring an activity within scope. Operators we advise frequently discover mid-build that an architecture they considered internal or custodial has been classified as transmission by one or more state regulators.
How does FinCEN MSB registration work in practice?
FinCEN MSB registration is a self-registration through the BSA E-Filing System — there is no approval process, only a registration that must be completed before operations begin and renewed every two years. The substance of the obligation lies in what follows: a written AML/CFT program, a designated compliance officer, transaction monitoring, suspicious-activity reporting, and currency-transaction reporting where thresholds are met under the applicable FinCEN provisions.
For an on/off-ramp business, the AML program must address the specific risks of converting between fiat and virtual assets. FinCEN has issued guidance making clear that exchangers and administrators of convertible virtual currency are MSBs. A business that fails to register, or registers but operates without a compliant AML program, faces civil money penalties and, in serious cases, criminal referral. We have seen enforcement actions framed primarily as AML failures rather than unlicensed money-transmission charges — the two often travel together.
Separately, the Travel Rule (the obligation to pass originator and beneficiary data with a transfer above the applicable threshold) applies to MSBs under FinCEN rules. For crypto-fiat on/off-ramps, the practical question is how to collect, validate, and transmit that data when one leg of the transaction touches a blockchain. Compliance infrastructure for this is a pre-licensing requirement in our practice, not an afterthought.
To map your federal registration obligations and AML program requirements before launch, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your entity structure, the states where your users sit, and your banking arrangements change the analysis materially.
What does the state MTL application process actually require?
State MTL applications are the most resource-intensive part of the U.S. licensing stack, and they run concurrently with FinCEN registration, not sequentially. Most states require submission through the Nationwide Multistate Licensing System (NMLS), which standardizes a portion of the documentation but does not standardize the substantive requirements — each state retains its own capital minimums, surety bond amounts, permissible investments, and examination standards.
A typical state application requires: a business plan describing the transmission activity; audited or certified financial statements; background checks and fingerprinting for principals, officers, and major shareholders; a surety bond in a state-specified amount; evidence of minimum net worth or capital; an AML/BSA policy; and a sample customer agreement. Some states additionally require a cybersecurity assessment or a description of the technical architecture for the virtual-currency component of the business.
Timelines vary. Some states process applications within weeks; others, particularly those with higher volumes of pending applications, take many months. The NYDFS BitLicense process is among the longest and most demanding in the country, with applicants routinely engaging in extended back-and-forth with examiners before a determination is issued. In our cross-border practice, we advise operators to treat state licensing as an 18-to-24-month program for full national coverage, with an early-priority state set chosen to match the initial user geography.
Several operators pursue a money-transmitter licensing agreement (MTLA) with an already-licensed partner — sometimes called a "banking as a service" or BaaS arrangement — to access state-licensed rails during the period their own application is pending. This is a viable interim model, but the regulatory responsibility for the licensed partner's conduct still sits with the sponsor, and regulators have moved to tighten oversight of these arrangements in recent years.
Why does the NYDFS BitLicense matter even for non-New York businesses?
The NYDFS BitLicense applies to any entity conducting virtual-currency business activity involving New York residents — the jurisdictional trigger is user location, not entity domicile. A crypto exchange incorporated in Wyoming, or a payments business domiciled offshore, that accepts New York-based customers for fiat-to-crypto conversion is within the BitLicense perimeter. This is the provision most frequently underestimated by inbound operators and foreign exchanges adding U.S. fiat rails.
The BitLicense requires a separate application to the New York Department of Financial Services, distinct from the standard NMLS MTL process. NYDFS examines the business in depth: its capital, cybersecurity posture, consumer-protection arrangements, and AML program. The application fee is substantial, the documentation requirements are extensive, and the NYDFS has broad discretion to condition, limit, or deny a licence.
NYDFS has also issued a Greenlist of approved coins — virtual currencies that BitLicense holders may offer without seeking prior approval. Adding an unlisted coin requires a prior-approval process. For token issuers adding fiat rails to a new asset, this creates a sequencing challenge: the on/off-ramp cannot go live for New York users until the underlying asset clears NYDFS review.
In our practice, we regularly advise operators to assess New York exposure at the product-design stage. A deliberate, documented decision to geo-block New York users — consistently enforced — can remove the BitLicense requirement, but the block must be technically robust and the decision must be memorialized. A soft block that a user can circumvent with a VPN does not achieve regulatory insulation.
Why is banking access the most acute operational risk for U.S. on/off-ramp businesses?
Holding the right licences does not guarantee a bank account. U.S. banks remain deeply cautious about crypto-related deposit accounts, and the de-risking posture of the largest correspondent banks has materially narrowed the options for even well-licensed on/off-ramp businesses. Several high-profile bank closures and regulatory actions in recent years accelerated this caution, leaving a smaller set of banks actively willing to serve crypto businesses at scale.
The banks that do serve licensed crypto businesses typically require extensive due diligence: audited financials, demonstrated AML program quality, transaction-monitoring reports, and an explanation of the crypto-fiat flow at a technical level. Onboarding timelines are long — often several months — and accounts are subject to ongoing monitoring and periodic re-underwriting. A change in ownership, a new product, or a regulatory inquiry at any point can trigger a review or closure.
For on/off-ramp businesses, the cross-border dimension compounds the challenge. A business whose parent entity sits offshore, whose custody layer is in one jurisdiction, and whose users are in another presents a risk profile that most U.S. bank compliance teams will not readily accept. We map this structure explicitly in banking-onboarding mandates: the entity that holds the MTLs, the entity that holds customer fiat, and the entity that interacts with the blockchain must each be positioned to survive the bank's BSA/AML review.
EMIs licensed in the EU under the Payment Services Directive (PSD2) or in the UK can, in certain architectures, provide an alternative fiat clearing layer for the non-U.S. legs of an operation. However, an EMI cannot substitute for a U.S.-licensed structure when the customers are U.S. persons — the licensing perimeter follows the user, not the entity. A common architecture splits the U.S.-person fiat leg to a U.S.-licensed entity and routes non-U.S. fiat through an EMI, with careful structuring to avoid co-mingling that would bring the offshore entity within U.S. scope.
If prior banking applications stalled or an account was closed without explanation, a second structural read can surface the reason. Write to OBOLUS at info@oboluslaw.com.
How do federal and state MTL requirements interact with a cross-border structure?
A foreign exchange or payments business adding U.S. fiat rails faces a structural decision that must be made before the first compliance document is filed. Operating through a U.S. subsidiary requires the subsidiary to hold all required MTLs in its own name — the foreign parent's licensing history in another jurisdiction provides no relief. The subsidiary must be capitalized appropriately, staffed with a qualified compliance officer, and governed in a manner that satisfies state examiners who will look closely at the relationship between the parent and the licensed entity.
Where a foreign business directs U.S. persons to a non-U.S. platform for fiat conversion, the argument that the activity occurs offshore is difficult to sustain. FinCEN's guidance and state regulators' enforcement practice consistently look to the location of the customer, not the server. Operators we advise who have relied on offshore-only structures for U.S.-person fiat activity have, in almost every case, needed to retrofit a U.S.-licensed entity — often under time pressure.
Tax interacts with the cross-border structure at two points. First, a U.S.-incorporated subsidiary or a foreign company "doing business" in the U.S. may be subject to federal and state income tax on income connected to U.S. sources, including fiat-conversion fees. Transfer pricing between the U.S. entity and a foreign parent — for technology, risk, or compliance services — must be documented and defensible. Second, reporting obligations for cross-border fiat flows (FinCEN Form 114 / FBAR; FATCA for foreign financial account holders) apply to the entities and, in certain cases, to the individual controlling persons. We work with allied tax counsel in the relevant jurisdictions to align the licensing structure with the tax and reporting posture before filing season arrives.
What does this look like in practice?
In a recent matter, a payments company incorporated in a leading offshore centre sought to add U.S. fiat on-ramp capability for its retail-facing crypto product. The company had an MSB registration on file but had not filed MTLs in any state, and its U.S. user base had grown organically to cover more than thirty states. We conducted a retroactive gap analysis, identified the highest-risk states by enforcement posture and user concentration, and coordinated a sequenced NMLS application program beginning with those states. Simultaneously, we advised on a corporate restructuring to place the U.S.-licensed function in a Delaware-incorporated subsidiary, isolating the MTL holder from the offshore parent's broader liability profile. The banking engagement was reopened on the basis of the subsidiary structure, and the operator obtained a Tier 1 U.S. banking relationship within the application period. The matter illustrates how an unaddressed structural gap — common in fast-scaling businesses — can be worked through methodically with the right sequencing.
Which operator profile maps to which U.S. licensing approach?
The right approach depends on the operator's existing licence stack, user geography, and risk appetite. Three profiles are most common in our practice.
Profile A — Greenfield U.S. launch: A new business building for U.S. users from the outset should incorporate a U.S. entity, file FinCEN MSB registration immediately, and begin the NMLS MTL process in the states matching its initial product geography. The NYDFS BitLicense process should be assessed at the same time, even if New York launch is deferred. The timeline to full national MTL coverage is measured in years, not months; banking onboarding begins in parallel with the first state applications. Key risk: undercapitalization relative to surety bond and net-worth requirements across multiple states.
Profile B — Foreign exchange adding U.S. rails: A non-U.S. exchange with an existing global user base planning to add U.S. fiat capability should establish a U.S. subsidiary, transfer or originate the MTL stack in the subsidiary's name, and ring-fence U.S.-person activity at the product level before the subsidiary is licensed. An interim BaaS or MTLA arrangement with a licensed partner can provide operational rails during the application period. Key risk: state regulators scrutinizing the affiliate relationship between the subsidiary and the foreign parent and imposing conditions on the licence.
Profile C — Non-U.S. business with incidental U.S. exposure: A business primarily serving non-U.S. users that has accumulated a U.S. user base through organic growth should immediately assess its MTL and BitLicense exposure, implement a documented geo-blocking or user-verification process to limit further U.S. onboarding, and determine whether the U.S. user base justifies a licensed U.S. structure or requires active off-boarding. This profile carries the highest retroactive enforcement risk and typically requires urgent legal engagement.
Related at OBOLUS
- Banking, Payments & EMI Onboarding for Digital-Asset Businesses – how we structure fiat rail access across multiple regulatory regimes
- De-risking and Account Closure Defence in El Salvador – strategy when a bank terminates a crypto business account
- Crypto Exchange Setup in Hong Kong – VASP licensing and fiat rail considerations under SFC supervision
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because of BSA/AML risk appetite — not legal prohibition. Most U.S. banks apply heightened due diligence to crypto businesses, and when a company cannot demonstrate a well-documented AML program, clear beneficial ownership, and a licensing posture that matches its actual user base, the bank's compliance function will typically exit the relationship. Regulatory pressure on bank sponsors of BaaS arrangements has intensified this pattern. The structural fix is usually a cleaner entity architecture paired with a stronger compliance file, not a search for a different bank.
How can a VASP onboard with an EMI?
A virtual asset service provider (VASP) seeking to onboard with an EMI licensed under PSD2 or the UK Payment Services Regulations must pass the EMI's own customer due-diligence process, which typically mirrors a bank's: AML policy review, ownership structure, source of funds for customer deposits, and an explanation of the fiat-to-crypto flow. EMIs that serve VASPs do so under their own regulatory risk framework, and they will gate access on the VASP's licensing status in the relevant jurisdiction. A U.S. VASP using an EU EMI for non-U.S. fiat legs must ensure the arrangement does not inadvertently bring U.S.-person flows within scope of the EMI, which lacks U.S. authorisation.
What does client-money safeguarding require?
Client-money safeguarding in the U.S. context requires, at minimum, that customer fiat is held in a segregated account — separate from the business's own funds — at an FDIC-member institution or an equivalent. State MTL regimes typically specify permissible investments for customer funds held pending transmission and impose reporting obligations on those balances. Several states require a trust company charter or a specific custody arrangement for fiat held for extended periods. Where the safeguarding obligation interacts with crypto custody — for example, in a stablecoin issuance model — the analysis extends to reserve composition and the applicable provisions under MiCA or the NYDFS framework, depending on the issuer's domicile.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, and payments companies on licensing across more than 70 jurisdictions, on disputes and on-chain asset recovery across more than 25 forums, and on the tax, banking, and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody, and payment layers before you commit — and our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when things go wrong. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst — specialising in federal and state money-transmitter licensing, FinCEN MSB compliance, and the cross-border regulatory positioning of digital-asset payments businesses in the U.S. market.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.