EST · MMXXVI
Home/Services/Banking Payments Emi/Client funds safeguarding for Early-stage Founders
Banking, Payments & EMI Onboarding

Client funds safeguarding for Early-stage Founders

Client funds safeguarding for Early-stage Founders. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Operating a digital-asset business without properly segregated client funds is one of the fastest routes to regulatory enforcement, frozen rails and permanent account closure. For early-stage founders, the question is not merely academic: regulators across every major hub now treat client-money safeguarding as a licensing prerequisite, not an operational afterthought. Understanding the regime, structuring the accounts correctly and choosing the right payment partners before you launch is the difference between a business that scales and one that stalls at the first compliance audit.

Client funds safeguarding – the legal obligation to hold customer money separately from operational funds, in a ring-fenced account with a regulated institution – sits at the intersection of payment regulation, prudential rules and anti-money-laundering regimes. Under MiCA, the EU's Markets in Crypto-Assets Regulation, and under the payment services frameworks of every leading hub, a crypto-asset service provider that receives or holds client funds must comply with explicit safeguarding requirements or face licence suspension. This page explains what founders need to know, how to structure it and where the common mistakes arise.

Why Safeguarding Matters More Than Founders Expect

Safeguarding is not a formality. It is the structural condition on which banking relationships, EMI onboarding and regulatory authorisation all depend. Regulators in Dubai under VARA, in Singapore under the MAS Payment Services Act, and across the EU under MiCA each embed safeguarding obligations at the licence-category level. A business that conflates client money with working capital – even briefly – triggers a breach that can cascade into account suspension, regulatory investigation and personal liability for directors.

In our practice, we see early-stage founders make this mistake at the pre-revenue stage, before formal licensing. The assumption is that safeguarding rules apply only after a licence is granted. In practice, many regulators assess safeguarding arrangements as part of the authorisation application itself. Presenting a credible safeguarding plan – named accounts, named institution, documented sweep mechanics – is the entry ticket, not the graduation prize.

The cross-border dimension compounds the risk. A founder incorporated in the BVI, serving European users through an EU-registered entity and banking through a payment institution in Lithuania, faces three distinct safeguarding regimes simultaneously. Each layer carries its own obligation, its own documentation standard and its own regulatory enforcer. Mapping all three before launch is not optional.

What the Regulated Basis Actually Requires

The core obligation under most payment and crypto-asset regimes is simple to state and complex to implement: client funds must be held in a designated account, clearly segregated from the firm's own funds, with a credit institution or regulated money-market instrument. The firm cannot use client money to fund operations, meet payroll or settle its own debts.

Under the applicable provisions of MiCA, crypto-asset service providers (CASPs) that hold client funds are required to maintain safeguarding arrangements consistent with the payment institution standards already established under EU payment services law. The practical implication: a CASP authorised in one EU member state and passporting across the EU/EEA must demonstrate, at authorisation, that a qualifying credit institution has agreed in writing to hold those funds on the correct basis.

The FCA in the United Kingdom applies a similar standard under its payment services rules, requiring registered crypto firms to demonstrate ring-fenced account arrangements before AML registration is confirmed. VARA in Dubai goes further: its custody and transfer-settlement rulebooks specify the governance structure around client money, including board-level accountability for safeguarding policy. MAS in Singapore applies comparable requirements under the Payment Services Act for Digital Payment Token service licensees.

The common thread is institutional: a letter of intent from a friendly neobank does not satisfy the requirement. The regulator wants a named, regulated credit institution or EMI, a countersigned account agreement and documented processes for daily reconciliation and shortfall detection.

CTA #1 – The safeguarding structure above describes the standard path. Your facts – the entity, the user base, the banking relationship – change the analysis materially. Map your options before the application is filed.

How Does EMI Onboarding Work for Crypto Founders?

An EMI (Electronic Money Institution) is a regulated entity that can issue electronic money, maintain payment accounts and provide payment services – making it the most common banking-layer partner for early-stage crypto businesses that cannot yet access a full correspondent banking relationship. EMI onboarding for a crypto company is a structured compliance process, not a commercial sales conversation.

The EMI's compliance team will conduct its own assessment of the crypto applicant. That assessment typically covers: the source of the business's crypto revenues, the AML/KYC programme in place, the jurisdictions from which clients are onboarded, the product type (exchange, custodian, OTC desk, token issuer) and the projected transaction volumes. A crypto business that cannot answer these questions in a structured compliance deck will not be onboarded – or will be onboarded on terms that make the relationship fragile.

In our cross-border practice, we have seen three EMI onboarding patterns for early-stage founders. First, the founder approaches a crypto-friendly EMI directly, without legal preparation, and is declined after a superficial due-diligence call. Second, the founder engages an introducer who places the account at an EMI that is itself under regulatory pressure – and the account is closed within months when the EMI loses its own authorisation or tightens its crypto policy. Third – the pattern that works – the founder prepares a complete compliance pack, selects an EMI whose own licence is stable and whose crypto risk appetite matches the business profile, and negotiates account terms before the application is submitted.

The cross-border angle matters here too. An EMI authorised in Lithuania under Bank of Lithuania supervision can passport payment services across the EU. That makes Lithuanian EMIs a common choice for EU-facing crypto businesses. But passporting does not automatically extend safeguarding protections to clients in all member states, and the local rules of the destination country may impose additional requirements on the crypto business itself.

What Common Mistakes Cost Founders Their Banking?

De-risking – the practice by which banks and EMIs close accounts of clients they consider too risky – is the single biggest operational threat to early-stage crypto businesses. Most de-risking events are not random. They follow a predictable pattern of preventable errors.

The first mistake is entity structure. Founders often incorporate an offshore holding company and attempt to open a payment account in that name, without a regulated operating subsidiary in the jurisdiction where the account sits. Banks and EMIs assess the regulatory status of the legal entity making the application, not the group. An unregulated BVI holding company applying to a UK or EU EMI will almost always be declined.

The second mistake is the absence of a licence, or the presence of the wrong one. A single offshore VASP registration – say, under the BVI VASP Act or the Cayman VASP regime – is not equivalent to a MiCA CASP authorisation or a MAS DPT licence. EMIs in regulated jurisdictions are required to assess whether their crypto clients hold the correct local licence for the services they provide. If the answer is no, onboarding is refused or the account is closed on review.

The third mistake is transaction-monitoring gaps. EMIs perform ongoing monitoring of account activity. A crypto business whose clients send large, irregular transfers without adequate source-of-funds documentation will trigger alerts. If the business cannot produce a structured response – a defined TM procedure, documented escalation path, named MLRO – the EMI will exit the relationship, often with 30 days' notice and no obligation to explain.

The fourth mistake is geography. Serving clients from sanctioned jurisdictions, or from markets where the crypto business has no local licence, creates a compliance exposure that EMIs cannot accept. Founders who build without mapping the jurisdictional perimeter of their client base routinely discover this problem at the worst possible moment.

Decision Matrix: Which Safeguarding Structure Fits Which Founder Profile?

Not every early-stage business needs the same safeguarding architecture. The right structure depends on the business's regulatory status, the jurisdictions it serves, the volume of client money it holds and the speed at which it needs to open fiat rails.

Profile A – Pre-licence, EU-facing, sub-threshold volumes. A founder in the pre-authorisation phase serving EU retail users at low volumes should prioritise obtaining a MiCA CASP authorisation or, as an interim measure, a transitional registration in a member state that offers one. The safeguarding account should be opened at an EMI that explicitly accepts clients under MiCA transitional status, with a formal agreement documenting the ring-fence. Timeline to first operational account, assuming the compliance pack is complete: a matter of weeks to a few months, depending on the EMI and the member state.

Profile B – Regulated entity, multi-jurisdictional user base. A business that holds a single licence – a VARA licence in Dubai, for example, or a Singapore DPT licence – but serves clients in multiple markets needs a more complex structure. The safeguarding account in the primary jurisdiction covers client money from clients where that licence is valid. For other markets, the business needs either a local licence or a clear legal opinion that no licence is required. Banking across jurisdictions typically involves a primary EMI account, a correspondent arrangement and documented processes for cross-border fund movements. Indicative timeline to a fully operational multi-rail structure: several months.

Profile C – Token issuer, no ongoing custody of client fiat. A business that issues tokens and does not hold ongoing client fiat balances faces a lighter safeguarding obligation, but is not exempt. Under MiCA, token issuers that receive fiat for token purchases must comply with the applicable whitepaper and issuer obligations, which include reserve and safeguarding requirements for asset-referenced tokens (ARTs) and e-money tokens (EMTs). The safeguarding structure for a token issuer is product-specific and should be defined before the whitepaper is filed.

The Cross-border Fiat Rails Reality for Crypto Businesses

Fiat rails – the banking, payment and settlement infrastructure through which a crypto business moves customer money – are the operational dependency that most founders underestimate. A crypto business can build a technically flawless product and still fail if it cannot move money reliably in and out of the on-chain environment.

The cross-border reality is this: a business incorporated in one jurisdiction, licensed in a second and serving clients in a third must manage three sets of rules for every fiat transaction. The jurisdiction of incorporation governs corporate law and beneficial ownership. The jurisdiction of licensing governs the regulatory obligations around client money. The jurisdiction of the client governs any local payment-services or crypto rules that apply at the point of service.

In our experience, the fiat rails problem typically surfaces in one of three ways. First, the business's primary bank exits the relationship after a routine compliance review, and the business has no secondary banking in place. Second, the business's EMI loses its own authorisation or voluntarily exits the crypto segment, taking the client accounts with it. Third, the business expands into a new market – Latin America, the Gulf, Southeast Asia – without first confirming that its existing banking infrastructure can process transactions from that market without triggering a de-risking response.

Each of these events can be anticipated and, to a significant degree, mitigated. The mitigation is structural: multiple banking relationships, documented contingency protocols and a clear legal map of what each banking partner can and cannot do for each client segment.

Micro-matter: In a recent matter, an early-stage exchange had secured a single EMI relationship for all client money, relying on that account for both custody and operational flows. When the EMI exited its crypto portfolio following a regulatory review, the exchange lost access to its primary fiat rail overnight. We were engaged to map alternative structures, negotiate with a replacement institution and document the interim safeguarding arrangements. The new banking structure – splitting custody accounts from operational accounts across two regulated institutions in different member states – was in place within a few weeks, and the business maintained uninterrupted client services throughout.

Self-Assessment: Is Your Safeguarding Structure Fit for Licensing?

Before submitting a licence application or approaching an EMI, a founder should be able to answer each of the following questions affirmatively. An honest assessment of gaps at this stage is far less costly than discovering them during regulatory review.

  • Does the operating entity hold, or is it applying for, the correct licence in each jurisdiction where it holds client funds?
  • Have you identified a named, regulated credit institution or EMI willing to provide a safeguarding account on documented terms?
  • Is the safeguarding account formally ring-fenced from operational accounts, with a documented daily reconciliation process?
  • Does the business have a written AML/KYC programme, a named MLRO and a documented transaction-monitoring procedure?
  • Have you mapped the jurisdictions of your client base and confirmed that your licence and banking cover each of them?
  • Does the business have at least one secondary banking relationship, or a documented contingency plan for primary-bank failure?
  • Has the safeguarding structure been reviewed by counsel against the applicable regime – MiCA, VARA, MAS, or another – rather than inferred from commercial guidance alone?

If any answer is no, the gap should be addressed before the application is filed. Regulators assess readiness, not intent.

CTA #2 – If a prior application stalled, an account was closed or a regulator has raised concerns about your safeguarding structure, a second read can surface the structural reason and the route forward. Map your options with the OBOLUS banking and payments team.

A Common Assumption About Offshore Licensing

A common assumption among early-stage founders is that a single offshore licence – a BVI VASP registration or a Cayman VASP listing – provides the legal cover needed to operate globally and access banking in any jurisdiction. This assumption is incorrect, and acting on it is one of the most reliable ways to lose banking access.

Offshore registrations under the BVI VASP Act or the Cayman VASP regime serve a real purpose: they establish that the entity is a regulated VASP in its home jurisdiction. But they do not constitute a MiCA CASP authorisation, a MAS DPT licence or a VARA activity licence. An EMI in the EU assessing whether to onboard a crypto client will look at whether the client holds the licence that corresponds to the services it provides in the EU – not whether it holds any licence at all. The two are not the same.

Similarly, a VARA licence in Dubai does not authorise the holder to conduct crypto-asset services in Singapore or the UK. Each jurisdiction maintains its own perimeter, and serving clients across that perimeter without the corresponding licence exposes the business to enforcement in each market independently. The practical consequence: a multi-jurisdictional crypto business needs a licence stack, not a single registration, and the stack must be mapped to the actual geography of the client base.

This is not a criticism of offshore structures. BVI and Cayman entities remain valuable components of a well-designed crypto corporate structure – for holding, investment vehicle and governance purposes. The error is using them as the sole regulatory basis for an operating business that touches client money across multiple jurisdictions.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily because of perceived AML/CFT risk, compliance gaps in the client's KYC and transaction-monitoring programmes, or a mismatch between the client's licence status and the services it provides. Regulatory pressure on banks to manage their own correspondent-banking exposure has made the crypto sector a systematic de-risking target. A business with documented AML procedures, a clear licence map and stable transaction patterns significantly reduces the risk of involuntary closure.

How can a VASP onboard with an EMI?

A VASP seeking EMI onboarding must present a complete compliance pack: corporate structure, regulatory status (licence or registration in the relevant jurisdiction), AML/KYC programme with named MLRO, transaction-monitoring procedures, source-of-funds documentation and projected volumes by client geography. EMIs conduct their own due diligence and assess whether the VASP's regulatory status matches the services it will use the account for. Preparation and selection of a compatible EMI are the two variables most within the applicant's control.

What does client-money safeguarding require?

Client-money safeguarding requires that funds received from clients are held in a dedicated, ring-fenced account at a regulated credit institution or EMI, entirely separate from the firm's own operational funds. The applicable regime – MiCA for EU CASPs, the MAS Payment Services Act for Singapore DPT licensees, VARA rulebooks for Dubai, the FCA's rules in the UK – determines the precise documentation, reconciliation frequency and shortfall-notification obligations. A written safeguarding policy, a countersigned account agreement and daily reconciliation records are the baseline in most major regimes.

About OBOLUS

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and early-stage founders on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the banking, payment and compliance structures that sit around them. Digital assets are the entirety of our practice. We map the licence stack across operating, custody and payment layers before you commit – because restructuring after launch costs multiples of what prevention costs. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in payment services licensing, EMI onboarding strategy and client-money compliance for digital-asset businesses across EU, Gulf and Asia-Pacific hubs.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours