EST · MMXXVI
Home/Practices/Banking, Payments & EMI Onboarding for Digital-Asset Businesses
Banking, Payments & EMI Onboarding

Banking, Payments & EMI Onboarding for Digital-Asset Businesses

Banking, Payments & EMI Onboarding for Digital-Asset Businesses. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Ta

Operating a digital-asset business without stable fiat infrastructure is not a regulatory inconvenience – it is an existential risk. Exchanges that cannot settle in dollars or euros, custodians that cannot pay staff, and token issuers that cannot convert treasury balances all share the same structural problem: banking, payments and EMI onboarding for crypto businesses is harder to secure, and easier to lose, than almost any other operational input. With supervisory scrutiny of crypto client portfolios intensifying across every major banking centre, the window for getting this right is narrowing.

The core legal question is not simply "which bank will take us?" It is: which combination of regulated instruments – a licensed electronic money institution, a direct banking relationship, a payment institution authorisation, or a hybrid structure – produces rails that are durable under the compliance policies of the counterparty, the regulatory expectations of the home regulator, and the cross-border realities of a user base that never sits in a single jurisdiction. We advise exchanges, custodians, token issuers and funds on precisely that question, mapping the licence stack across operating, custody and payment layers before any commitment is made.

This page sets out the regulated perimeter, the instrument options, the cross-border dynamics, and the structural mistakes that cost businesses their rails.

The Regulated Perimeter: What Triggers a Payment or EMI Authorisation?

A digital-asset business touches the payment regulatory perimeter the moment it holds, moves, or converts fiat currency on behalf of clients – and the threshold for "on behalf of clients" is lower than most operators assume. The relevant regimes – MiCA at the EU level, the FCA's payment services rules in the UK, MAS under Singapore's Payment Services Act, and equivalent frameworks in the UAE under VARA and in the AIFC under AFSA – each draw the perimeter around the economic substance of the activity, not the label the business applies to it.

An exchange that receives euro deposits from retail clients before converting them into bitcoin is, in most EU jurisdictions, providing a payment service. A custodian that sweeps client funds overnight into a pooled account may be holding e-money. A DeFi protocol that routes fiat on-ramp flows through a proprietary smart contract is not automatically outside the perimeter because the intermediary is code rather than a firm. Regulators in the leading hubs increasingly expect operators to analyse every fiat-touching touchpoint in their product and apply the applicable regulatory characterisation to each one.

The consequences of mischaracterisation are severe. Operating a payment or e-money activity without the appropriate authorisation triggers enforcement exposure, potential criminal liability for directors, and – critically – gives correspondent banks a documented basis to close accounts without notice. In our cross-border practice, we see operators discover this exposure only after a bank exit has already occurred.

Contact OBOLUS before you build the fiat layer. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. For a scoped assessment of your payment regulatory perimeter, contact OBOLUS at info@oboluslaw.com.

Why Do Banks Exit Crypto Clients – and What the Pattern Tells Operators?

Banks close crypto company accounts for a combination of compliance risk appetite, correspondent bank pressure, and documented regulatory expectation – not because crypto is inherently unbankable. Understanding the actual mechanism matters, because the response to each cause is structurally different.

The most common immediate trigger is a correspondent bank directive: the local bank's USD or EUR correspondent imposes a blanket policy against crypto-exposed clients, leaving the local bank no margin to retain the relationship regardless of the individual client's compliance posture. The second trigger is a deficiency in the client's own AML/KYC documentation – missing transaction monitoring policies, incomplete beneficial ownership records, or a travel-rule implementation that the bank's compliance team cannot map to a recognised framework. The third trigger is regulatory ambiguity: where a client's activity sits in a grey area of the applicable regime, banks err on the side of exit.

Each of these causes has a known legal response. Correspondent pressure is managed by restructuring the entity to hold a payment licence or EMI authorisation that places it within a regulated tier the correspondent recognises. AML documentation gaps are remediated through a policy rebuild aligned to the FATF Recommendations, including the Travel Rule obligation to pass originator and beneficiary data with each qualifying transfer. Regulatory ambiguity is resolved by obtaining a formal legal opinion or a regulatory no-action position in the home jurisdiction.

In our practice, we regularly advise businesses that have already suffered a bank exit. The structural cause is almost always traceable to one of these three patterns. The remediation path exists – but it takes longer when the exit has already happened than when the structure was built correctly at the outset.

The Instrument Map: Direct Banking, EMI, PI, or Agent Model?

Four principal instruments are available to a digital-asset business seeking durable fiat rails, and the right choice depends on the business model, the jurisdictions served, and the regulatory capital the operator is willing to deploy.

Direct banking – a corporate account at a licensed bank – is the simplest instrument and the hardest to obtain for a crypto-native business. Banks that actively serve the sector are concentrated in a small number of jurisdictions: Switzerland under FINMA supervision, certain EU member states under MiCA-transitional regimes, Mauritius under the applicable VAITOS framework, and a handful of specialist institutions in Singapore and the UAE. Direct banking provides the cleanest settlement mechanics but offers no regulatory status in its own right: the business is a customer, not a regulated entity, and the relationship can be terminated on the bank's standard notice period.

An electronic money institution (EMI) authorisation – in the EU, the UK, or an equivalent regime – converts the operator from a bank customer into a regulated entity in its own right. The EMI can issue e-money, hold client funds in safeguarded accounts, and in the EU passport the authorisation across member states under MiCA's complementary framework. The capital requirement, the governance obligation, and the AML supervision burden are real, but the authorisation provides a floor of legitimacy that correspondent banks recognise.

A payment institution (PI) authorisation is narrower: it covers specified payment services without the e-money issuance right. For a crypto exchange that needs to receive fiat deposits, execute conversions and remit proceeds, a PI authorisation may be sufficient and is generally faster and less capital-intensive to obtain than a full EMI licence.

The agent or distributor model – where the digital-asset business operates as an agent of an already-licensed EMI or PI – offers speed at the cost of control. The principal EMI is responsible for compliance and bears the regulatory risk; the agent is subject to the principal's policies and can be offboarded. For businesses in early-stage or testing phases, the agent model provides a legitimate path to fiat rails without the lead time of a full authorisation. For businesses at scale, it creates a dependency that a regulatory event can sever overnight.

What Does the Cross-Border Reality Look Like for a Crypto Business Seeking Banking?

Almost no digital-asset business sits in a single jurisdiction. The entity may be incorporated in the BVI, licensed under VARA in Dubai, serving EU retail users, and banking through a Mauritius correspondent. Each of those layers carries its own regulatory expectation – and each expectation can create friction with the others.

The EU's MiCA regime imposes rules on crypto-asset service providers serving EU clients regardless of where the provider is incorporated. A CASP authorised in Lithuania or Malta can passport across the EU; a business incorporated in a third country cannot rely on passporting and must either obtain a CASP authorisation or limit its EU client-facing activity. The banking consequence is direct: an EU bank onboarding a crypto client that serves EU retail users will ask whether the client holds a CASP authorisation or is otherwise compliant with MiCA's third-country provisions. If the answer is ambiguous, the bank will decline.

In the UAE, VARA's activity-based licensing regime covers exchange, custody, brokerage and transfer services in mainland Dubai. A business licensed under VARA is recognised by the UAE banking sector, but its licence does not extend to EU, UK or Singapore clients unless the relevant local authorisation is also in place. In our cross-border practice, we map each jurisdiction's regulatory expectation against the client base before recommending the structure – because a licence that satisfies the home regulator but creates a gap in the customer jurisdiction generates the same banking problem from a different direction.

AFSA within the AIFC provides a common-law framework that bridges CIS and Asian investor bases; MAS in Singapore requires a Payment Services Act licence for digital payment token services; the FCA's registration and financial-promotion rules impose obligations on any business marketing to UK persons. A multi-jurisdiction stack is not a sign of structural excess – it is the practical consequence of serving a global user base.

To map the licence, banking and tax stack for your build, write to info@oboluslaw.com. If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back.

How Does EMI Onboarding Actually Work for a VASP?

Onboarding a VASP (virtual asset service provider) with an EMI is a structured compliance process that typically runs over several weeks, not the overnight account-opening that a standard business might expect. Understanding the stages allows an operator to prepare correctly and avoid the documentation failures that produce rejections.

The EMI's intake process begins with a business model review. The compliance team maps every fiat-touching activity – deposit receipt, conversion, withdrawal, treasury management – against its own internal risk appetite and the applicable AML rules. For a crypto business, this review is more detailed than for a standard payment institution client, because the EMI must be satisfied that the VASP's own AML/KYC controls are adequate to meet the EMI's regulatory obligations as the account holder's bank.

The documentation package a VASP should prepare includes: a current AML policy aligned to FATF standards; a Travel Rule implementation statement that explains which messaging protocol is used for qualifying transfers; a description of the transaction monitoring system, including threshold logic; beneficial ownership documentation to the ultimate individual level; and, where applicable, a copy of the VASP's own licence or registration in its home jurisdiction. A forensic-quality blockchain analytics tool report on the business's own wallets – showing no exposure to sanctioned addresses or high-risk counterparties – has become a near-standard expectation at leading EMIs in the past two years.

The jurisdictional location of the EMI matters for the client-money safeguarding regime that applies. In the EU, EMIs are required to safeguard client funds by holding them in segregated accounts at a credit institution or investing them in secure, liquid, low-risk assets – and the VASP as a client of the EMI benefits from this safeguarding as its own deposited fiat is ring-fenced. The UK FCA imposes materially similar safeguarding requirements under its payment services rules.

In a recent engagement, a mid-stage crypto exchange sought EMI onboarding in an EU jurisdiction after its prior banking relationship was terminated. We rebuilt the AML documentation package, drafted a Travel Rule implementation statement that mapped the exchange's protocol choice to the applicable FATF guidance, and coordinated with allied counsel in the relevant jurisdiction to address regulator-specific questions during the EMI's due diligence phase. Onboarding was completed within a commercially acceptable timeframe, and the exchange retained correspondent access throughout the transition.

What Does Client-Money Safeguarding Require of a Digital-Asset Business?

Client-money safeguarding is the regulatory obligation that prevents a payment institution or EMI from treating client fiat as its own working capital – and for a crypto business, it has direct implications for how treasury is structured, how insolvency risk is managed, and how banking arrangements are documented.

The core requirement, consistent across MiCA, the EU Payment Services framework, and the FCA's rules, is that client funds must be segregated from the firm's own funds. In practice, this means maintaining separate designated client accounts at a credit institution, reconciling those accounts daily against client liabilities, and not using client balances to fund operating expenses or trading positions. For a custodian or exchange that holds both crypto assets and fiat on behalf of clients, the safeguarding obligation applies to the fiat portion; the crypto portion is typically governed by the applicable custody regime.

The safeguarding obligation interacts with the banking structure in a specific way. If the bank holding the segregated client account exits the relationship, the safeguarding obligation does not pause while a replacement bank is found. The operator must have a contingency banking arrangement documented in advance – a second designated institution ready to receive the segregated balance – or it will be in breach of its regulatory obligations from the moment the primary account closes.

Operators we advise routinely underestimate this contingency requirement. A single banking relationship for client-money purposes is not a compliant structure in most leading regimes; it is a single point of failure that the regulator will identify on its next review. Building a secondary safeguarding arrangement – with a different institution in a different jurisdiction – is not a luxury for large-scale operators. It is a baseline expectation.

For a crypto business that does not yet hold a payment or EMI licence, safeguarding obligations may still arise indirectly: if the business is operating as an agent of a licensed EMI, the principal EMI's safeguarding requirements extend to the agent's activities, and the agent must comply with the policies the principal imposes.

AML, the Travel Rule, and What Banks Actually Check

A digital-asset business's AML posture is the single factor most banks cite as the basis for onboarding acceptance or rejection – and the standard they apply is rising, not falling. Understanding precisely what a bank's compliance team looks for is essential for any business preparing an onboarding package.

The Travel Rule (the FATF obligation to pass originator and beneficiary data with a qualifying virtual-asset transfer) is now a live expectation at almost every regulated EMI and payment institution that serves the crypto sector. The bank's compliance team will ask which Travel Rule messaging protocol the VASP uses, which counterparty VASPs it has verified as Travel-Rule-compliant, and what its policy is for transfers to or from unhosted wallets. A VASP that cannot answer these questions in writing, with a documented policy, will not pass a sophisticated EMI's compliance review.

Beyond the Travel Rule, the AML documentation the bank examines includes: the risk assessment underlying the business's AML policy; the customer due diligence standards applied to the VASP's own clients; the sanctions screening methodology (which list, which tool, what refresh frequency); and the suspicious activity reporting process. For a business that operates across jurisdictions, the bank will also ask how the AML policy addresses the differing regulatory standards of each jurisdiction the business serves.

Blockchain analytics is now a standard part of the bank's due diligence toolkit, not an optional enhancement. Tools used by leading forensic providers allow a compliance team to review a VASP's wallet exposure to sanctioned addresses, mixer services, high-risk exchanges, and ransomware-connected wallets. A VASP presenting to a bank without having run this analysis on its own wallets first is giving the bank's analysts the first look at data the VASP should have reviewed itself.

In our practice, we prepare the AML documentation package as an integrated deliverable – not as a set of standalone policies. The risk assessment informs the CDD standards; the CDD standards inform the transaction monitoring thresholds; the monitoring thresholds connect to the SAR process. Banks that review dozens of crypto-client onboarding packages per month can identify a documentation set assembled from templates quickly. Coherence – an AML framework that tells a consistent story about how the business actually operates – is the differentiator.

Which Structure Fits Which Profile?

The right banking and payment structure depends on the operator's profile – its business model, its jurisdictional footprint, its stage of development, and its risk tolerance. No single instrument suits every operator, and recommending one without analysing the others is the fastest route to a structure that works for six months and then fails when the business scales.

Profile A – Early-stage crypto exchange, single jurisdiction, no existing EMI relationship: The agent-of-EMI model provides the fastest path to fiat rails. The operator onboards as a regulated agent of a licensed EMI, gains immediate access to IBAN infrastructure, and operates under the EMI's compliance umbrella while it builds its own regulatory track record. The key risk is dependency on the EMI's continued willingness to carry the relationship. Indicative timeline: commercially available within a matter of weeks if documentation is complete.

Profile B – Growth-stage exchange or custodian, EU user base, seeking MiCA-compliant structure: A CASP authorisation in an EU member state, combined with either an in-house EMI licence or a strategic EMI partnership under a documented agency agreement, is the appropriate structure. The CASP authorisation satisfies the MiCA third-country restriction for EU clients; the EMI relationship provides the fiat-settlement layer. Indicative timeline: CASP authorisation timelines vary by member state and are a matter of months to over a year; the EMI onboarding runs in parallel.

Profile C – Established VASP, multi-jurisdiction user base, banking instability history: A multi-instrument stack – VARA or ADGM/FSRA licence in the UAE for the operating entity, an EMI or PI authorisation in an EU or UK jurisdiction for the payment layer, and a segregated safeguarding arrangement at a second institution in a different jurisdiction – provides the structural resilience that a single-bank, single-licence arrangement cannot. This profile requires the highest regulatory capital deployment but produces rails that are resistant to the correspondent-bank exit pattern that has damaged single-structure businesses. Key risk: coordination complexity across multiple regulators and external counsel.

Profile D – Tokenised fund or stablecoin issuer: The MiCA EMT (e-money token) or ART (asset-referenced token) regime may apply, requiring issuer authorisation rather than a CASP licence. The fiat-reserve management obligation – the requirement to hold backing assets in regulated, liquid, low-risk instruments – intersects directly with the banking structure. The issuer must maintain reserve accounts that meet MiCA's reserve composition expectations, and those accounts must be at institutions that can sustain the relationship under supervisory scrutiny.

What Are the Structural Mistakes That Cost Businesses Their Fiat Rails?

The structural mistakes that produce bank exits and EMI rejections are almost entirely avoidable – and almost entirely predictable. In our cross-border practice, we see the same patterns repeat.

The first and most common mistake is treating banking as an operational task rather than a legal one. A founder who opens a business account at a crypto-friendly bank without legal diligence on the bank's crypto policy, the bank's correspondent relationships, and the regulatory classification of the business's activity is building on unstable ground. The account may work for months; it will fail when the business grows to the point where it triggers the bank's risk escalation threshold.

The second mistake is single-jurisdiction thinking. A business licensed in one jurisdiction and banking in the same jurisdiction looks clean on paper. But if it serves clients in ten other jurisdictions, its banking partner is exposed to ten other regulatory environments it has not analysed. The bank's compliance team will eventually notice this – and the exit notice will arrive without the lead time the business needs to restructure.

The third mistake is treating AML documentation as a compliance formality rather than a banking asset. An AML policy that was written once and never updated does not reflect how the business currently operates. Banks that review it against the business's actual transaction flows – which they can do with blockchain analytics – will identify the inconsistencies. A documented, living AML framework that evolves with the business is not just a regulatory requirement; it is the primary instrument for retaining banking relationships.

A common assumption in the market is that a single offshore licence is sufficient to serve clients globally and satisfy banking partners in multiple jurisdictions. This is incorrect. A VARA licence addresses mainland Dubai; it does not satisfy an EU bank's MiCA compliance question. A BVI VASP registration does not give an MAS-regulated EMI the comfort it requires to onboard a client serving Singapore users. Each jurisdiction's banks apply their own regulatory standard to the client's licence portfolio.

Self-Assessment: Is Your Fiat Structure Actually Durable?

Before engaging counsel or approaching an EMI, a digital-asset business can run a preliminary structural assessment against the following questions. A "no" to any of them identifies a gap that requires legal attention before the banking conversation begins.

Does the business hold a licence or registration in every jurisdiction where it has retail-facing activity? Is the AML policy current, documented, and consistent with the actual transaction monitoring system in use? Has a Travel Rule implementation statement been prepared that identifies the messaging protocol, the counterparty verification process, and the unhosted-wallet policy? Has blockchain analytics been run on all business-controlled wallets, and is the result documented? Does the business have a secondary safeguarding account at a different institution from the primary? Has the regulatory classification of every fiat-touching activity been confirmed by legal opinion?

Operators we advise who can answer "yes" to all six questions are in a demonstrably stronger position when approaching a new EMI or bank. Those who cannot identify a clear answer to one or more questions have a structural gap that the EMI's compliance team will identify – and that we can address before it becomes a rejection.

When Should a Digital-Asset Business Engage Counsel on Banking and Payments?

The answer is earlier than almost every operator currently does. The cost of engaging legal counsel to review the payment regulatory perimeter, the AML documentation package, and the banking structure before approaching institutions is a fraction of the cost of rebuilding those elements after a bank exit or EMI rejection.

Specific triggers that indicate immediate legal engagement is appropriate: the business is launching a new product that touches fiat for the first time; it has received a bank exit notice; it is expanding into a new jurisdiction with a user base; it is applying for a CASP, VASP, EMI or PI authorisation; or it has received a regulatory inquiry that touches its payment or AML obligations. In each of these situations, the legal questions are live, the timeline is compressed, and the cost of delay compounds.

We structure licensing, banking and tax as one mandate rather than three disconnected workstreams. The payment regulatory analysis informs the licence selection; the licence selection informs the AML framework; the AML framework is what the bank evaluates. Treating these as separate workstreams – engaging a licensing consultant, a compliance vendor, and a bank independently – produces a structure where no single adviser is accountable for the coherence of the whole.

To pressure-test your structure before you commit, message us via t.me/oboluslaw.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks exit crypto clients for three principal reasons: correspondent bank pressure (the bank's own USD or EUR correspondent imposes a blanket restriction on crypto-exposed clients); deficiencies in the client's AML or Travel Rule documentation that the bank's compliance team cannot clear; and regulatory ambiguity where the client's activity is insufficiently characterised under the applicable regime. Each cause has a distinct legal remedy, ranging from entity restructuring to documentation rebuild to formal legal opinion. Treating all three as the same problem produces remediation plans that address the symptom rather than the cause.

How can a VASP onboard with an EMI?

A VASP onboarding with an EMI should prepare a comprehensive documentation package covering: a current AML policy aligned to FATF standards; a Travel Rule implementation statement identifying the messaging protocol and counterparty verification process; a transaction monitoring description with threshold logic; beneficial ownership documentation to ultimate-individual level; the VASP's home-jurisdiction licence or registration; and a blockchain analytics report on business-controlled wallets showing no exposure to sanctioned or high-risk addresses. The EMI's compliance review typically runs over several weeks. Documentation quality – particularly the coherence between the AML policy and actual operations – is the primary determinant of success.

What does client-money safeguarding require?

Client-money safeguarding under MiCA, the EU Payment Services framework and the FCA's rules requires that client fiat funds be held in designated segregated accounts at a credit institution, separate from the firm's own funds, reconciled daily against client liabilities, and not applied to the firm's operating expenses or trading positions. A compliant operator maintains at least one – and in practice ideally two, at different institutions – safeguarding account. Where a business operates as an agent of a licensed EMI, the principal's safeguarding requirements extend to the agent's client funds. A single safeguarding account with no contingency arrangement is a structural gap most regulators will identify on review.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – structuring licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com.

By Elena Frost, Partner – Compliance, AML/KYC, Travel Rule — advising digital-asset businesses on payment regulatory perimeter analysis, AML framework design, Travel Rule implementation, and EMI onboarding across EU, UK and multi-jurisdiction structures.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours