EST · MMXXVI
Home/Services/Banking Payments Emi/Client funds safeguarding for Institutional Clients
Banking, Payments & EMI Onboarding

Client funds safeguarding for Institutional Clients

Client funds safeguarding for Institutional Clients. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS

Institutional digital-asset businesses face a precise legal problem when they begin holding client money: the obligation to safeguard those funds is not a matter of best practice, it is a condition of operating lawfully. Client funds safeguarding – the legal requirement that a licensed payment institution or e-money institution (EMI) (a regulated firm authorized to issue electronic money and hold client balances) hold client balances in segregated, protected accounts – sits at the intersection of payment services law, prudential supervision and the practical reality of fiat rails (the bank accounts, correspondent lines and settlement infrastructure through which digital-asset businesses move money). For a crypto exchange, custodian or fund that also handles fiat, getting that structure wrong means frozen accounts, regulatory action, and clients who cannot access their own money. This page sets out the regulated basis, the process, and the cross-border decisions that determine whether your safeguarding structure holds under scrutiny.

Why Safeguarding Matters for Digital-Asset Businesses

Safeguarding is the legal firewall between client money and firm insolvency. In the leading regulated hubs – the EU under MiCA (Markets in Crypto-Assets Regulation) and the underlying payment services directives, the UK under FCA supervision, Singapore under the MAS Payment Services Act – a firm that holds client funds without proper segregation exposes those funds to its own creditors. The consequence for institutional clients is severe: in an insolvency, unsegregated client money becomes a general creditor claim. The firm's payment licence is also at risk.

Regulators in the major hubs increasingly expect not just formal segregation but documented, auditable evidence that safeguarding is functioning at all times. A licensed EMI or payment institution must typically hold client funds either in a segregated account at a credit institution or in covered assets, per the applicable regime. The specific rules on eligible assets, account structure and reporting frequency vary by jurisdiction and licence category – but the core principle is universal: client money must be insulated from firm money from day one of holding.

In our practice, we see institutional clients – funds, custodians, and multi-currency exchanges – underestimate how technical the operationalization of safeguarding is. Passing a licensing exam and having a policy document is not enough. The regulator will ask to see bank confirmation of segregated account status, internal reconciliation processes, and, increasingly, evidence of day-end reconciliation against client ledger balances.

For a regulated digital-asset business that also moves fiat, the safeguarding question and the banking question are inseparable. You cannot safeguard without a bank willing to hold the segregated account. And most banks require the regulated status first.

OBOLUS can map the sequence – regulation, then banking, then safeguarding structure – before you commit capital. The process above describes the standard path. Your facts – the entity, the user base, the banking arrangements – change the analysis materially. Map your options

The Regulatory Basis Across Key Jurisdictions

Safeguarding obligations arise from payment services and e-money law, not from crypto-asset law directly. A VASP (virtual asset service provider) that also transmits fiat – receiving client euros or dollars against crypto – typically triggers payment institution or EMI licensing alongside any VASP or CASP authorization it holds. The two regimes stack.

Under MiCA and the EU payment services regime, a CASP (Crypto-Asset Service Provider) authorized in one member state may passport across the EU and EEA – but payment services activities, including safeguarding, remain subject to the payment services directives enforced by national competent authorities. ESMA and those national authorities expect both layers to be satisfied. Lithuania's Bank of Lithuania and Malta's MFSA, historically popular EMI licensing venues, are both now aligning their supervisory expectations to the MiCA transition while maintaining payment services oversight in parallel.

In the United Arab Emirates, VARA in Dubai regulates virtual-asset activities including transfer and settlement. Firms that also handle client fiat interact with CBUAE (Central Bank of the UAE) regulated payment infrastructure. The safeguarding overlay in that environment is governed by the applicable CBUAE payment rules rather than VARA alone – a distinction that catches founders who assume a single VARA licence covers everything.

The FCA in the United Kingdom has maintained its own safeguarding rules under the Electronic Money Regulations and the Payment Services Regulations, alongside the crypto-asset financial promotion regime. UK-authorized EMIs must hold client funds in accounts designated as safeguarded, with supporting documentation that satisfies FCA expectations on eligible institutions. Post-Brexit, a UK EMI that passports into Europe is not available – a separate EU authorization is required, which is a structural decision many businesses have deferred too long.

In Singapore, MAS licenses digital payment token (DPT) service providers under the Payment Services Act. The Act's safeguarding requirements for client money apply to certain payment account services – the interaction with a DPT licence is fact-specific, but firms that hold both tokens and client fiat balances will typically face dual obligations. MAS has signaled that it expects robust operational controls, not just policy documentation, before granting or renewing authorization.

What Does Client-Money Safeguarding Require in Practice?

Operationally, client funds safeguarding requires a licensed firm to maintain a clear legal and accounting separation between client money and firm funds, supported by bank account structure, internal controls and documented reconciliation. The requirement is not satisfied by an internal ledger entry alone – the separation must be reflected in the banking relationship itself.

The core elements, common across the leading regimes, include:

  • A designated segregated account at an authorized credit institution, clearly titled to reflect its safeguarded status and restricted from firm use.
  • Written acknowledgment from the credit institution that the funds in the account belong to clients and are not available to the firm's general creditors.
  • A day-end reconciliation process that matches the aggregate client ledger balance to the aggregate bank balance, with a documented resolution process for discrepancies.
  • An internal safeguarding policy, reviewed at least annually, that specifies eligible institutions, eligible assets, concentration limits and the escalation process if a banking relationship ends.
  • Regulatory reporting – frequency and format vary by jurisdiction and licence class – demonstrating that safeguarding is maintained at all relevant reporting dates.

Where a firm holds client assets in covered assets (government bonds or similar instruments) rather than a bank account, additional requirements apply around asset selection, custody and mark-to-market monitoring. Most institutional operators start with the segregated bank account route and introduce covered assets only after the primary safeguarding infrastructure is proven.

Failure at any of these points is not a minor compliance gap. Regulators have suspended or revoked payment licences for inadequate safeguarding. In several documented instances across EU jurisdictions, firms discovered during a supervision visit that their bank's internal classification of the account did not match the firm's own records – resulting in a remediation requirement and a supervisory warning.

How Does EMI Onboarding Work for a Digital-Asset Business?

EMI onboarding – the process by which a digital-asset business establishes a regulated relationship with a licensed e-money institution – is the practical route for operators who need fiat account infrastructure without holding a payment licence themselves. Instead of applying for a licence, the business becomes a client of an EMI or payment institution that holds the requisite authorization and provides safeguarded accounts, IBAN issuance and payment processing under contract.

The attraction is real: time to market is faster, regulatory capital requirements fall on the EMI, and the operational burden of maintaining a safeguarding programme is outsourced. The limitation is equally real: the EMI's own risk appetite governs acceptance, and digital-asset businesses remain in the highest-scrutiny segment of that appetite.

In our cross-border practice, we regularly advise digital-asset businesses through EMI onboarding processes that have stalled or been declined. The common patterns are: (1) insufficient AML/KYC documentation at the entity level, particularly around ultimate beneficial owners; (2) a business model description that does not map cleanly to the EMI's regulatory permissions; and (3) a jurisdiction of incorporation or licensing that the EMI's compliance team has flagged as elevated-risk without a specific factual basis for that designation.

Each of these is addressable. A structured pre-submission package – including a regulatory summary, a business model analysis mapped to the EMI's permissions, and a compliance gap assessment – materially improves the outcome. The EMI needs to be able to demonstrate to its own regulator that it has conducted appropriate due diligence on this client. That demonstration is easier when the client has already done the analytical work.

The cross-border dimension matters here. An EMI licensed in Lithuania under the Bank of Lithuania may have risk parameters that differ from one authorized by the MFSA in Malta, or from a UK-authorized EMI operating post-Brexit. Where a business operates across multiple currency corridors – euro, dollar, dirham – a single EMI relationship is rarely sufficient. We map the multi-rail structure as part of the engagement, not as an afterthought.

Why Do Banks Close Crypto Company Accounts?

Crypto company account closures by banks follow a pattern that is well-documented in our practice: the trigger is rarely a specific compliance failure, and almost always a structural mismatch between the bank's risk model and the business's profile. Understanding that pattern is the first step to avoiding it.

Banks operating under AML/CFT supervision – FATF Recommendations, including Recommendation 15 on virtual assets, provide the international baseline – are required to apply enhanced due diligence to customers whose transactions carry elevated money-laundering or sanctions risk. Digital-asset businesses, by the nature of their transaction flows, typically fall within the highest-scrutiny tier of any bank's customer risk model. That is not a subjective judgment: it is a classification that the bank's regulator will review.

The specific triggers for account closure include: a change in the bank's risk appetite (often following a regulatory examination or enforcement action against another client); a transaction pattern that does not match the business profile on file; a jurisdiction change – incorporation, licensing, or banking – that triggers a re-screening; and a failure to respond adequately to an enhanced due diligence request within the bank's own SLA.

A common assumption among our clients is that holding a VASP or CASP licence automatically satisfies the bank's requirements. It does not. The licence is necessary but not sufficient. The bank needs to understand the specific business model, the source of funds flowing through the account, the client base profile, and the AML controls in place. Providing that information proactively – before the bank's compliance team asks for it – is the single most effective risk-mitigation step available to a digital-asset business managing its banking relationships.

In a recent banking matter, a regulated crypto exchange in a leading EU jurisdiction had its primary settlement account closed after the bank reclassified digital-asset businesses following an internal policy review. We prepared a structured response package – regulatory summary, transaction flow analysis, AML framework overview – and the account was reinstated within a matter of weeks. The outcome was not guaranteed; the process was disciplined.

Cross-Border Safeguarding: The Multi-Jurisdiction Reality

For an institutional digital-asset business operating across borders, safeguarding is never a single-jurisdiction question. The entity may be incorporated in one jurisdiction, licensed in a second, bank in a third, and serve clients in a fourth. Each layer carries its own regulatory expectation on how client money is held and reported.

A common structural error we see is a business that holds a VASP licence in a permissive offshore jurisdiction – say, a BVI registration under the FSC or a Cayman registration under CIMA – and assumes that structure is sufficient to service institutional clients in the EU or UK. It is not. The BVI FSC and CIMA maintain their own VASP registration regimes under the applicable VASP Acts, but neither confers the right to receive and hold client fiat balances from EU or UK-regulated institutions without triggering the payment services requirements of those markets. A Cayman fund structure and a BVI VASP registration do not substitute for MiCA CASP authorization or FCA registration when European or British institutional clients are involved.

The Travel Rule (the obligation under FATF Recommendation 16 to pass originator and beneficiary data with virtual-asset transfers) adds a further layer. Where a transfer crosses from a regulated VASP in one jurisdiction to a counterparty in another, both sides must satisfy the Travel Rule requirements of their own regulators. The data-transmission infrastructure required for Travel Rule compliance – and the compliance costs it generates – is part of the banking and payment structure that any serious institutional operator must plan for before the first client onboards.

For businesses sitting between a regulated hub (Dubai, Singapore, the EU) and an offshore domicile (BVI, Cayman), the legal question turns on where the regulated activity is actually performed, not where the entity is incorporated. Regulators in Dubai and Singapore have both issued guidance making clear that a legal-form structure in an offshore jurisdiction does not displace the regulatory perimeter of the hub where the operational activity occurs. Substance – staff, systems, decision-making, client-facing activity – is the determinant.

If a prior application stalled or an account was closed, a structured second read can surface the reason and identify the route back. To map the licence, banking and safeguarding stack for your build, write to info@oboluslaw.com. Map your options

Decision Matrix: Which Safeguarding Structure Fits Your Profile?

The right safeguarding structure depends on the operator's regulatory status, the volume and currency of client balances, and the jurisdictions of the client base. The matrix below describes the principal decision branches.

Profile A – Licensed payment institution or EMI (EU/UK/Singapore). The firm holds its own payment licence and must maintain safeguarding in-house. The obligation falls directly on the firm. The key decisions are: which credit institution will hold the segregated account, which assets are eligible under the applicable regime, and how the day-end reconciliation process is documented and audited. Timeline to implement a compliant structure: typically measured in weeks once the banking relationship is confirmed, though bank onboarding itself adds time. Key risk: the bank declines to issue the written acknowledgment of segregated status, which can delay the go-live date significantly.

Profile B – VASP or CASP without a payment licence. The firm transmits value in crypto but does not hold a payment licence. If it also receives and holds client fiat, it may be operating in the payment services perimeter without authorization. The immediate action is a regulatory mapping exercise to determine whether a payment licence is required in the operating jurisdiction. If not immediately obtainable, an EMI relationship under contract is the practical interim. Timeline for EMI onboarding: varies materially by EMI and by the completeness of the submission package, but typically a matter of weeks to a few months. Key risk: the EMI's compliance team classifies the business as too high-risk to onboard without additional structural changes.

Profile C – Institutional fund or custodian holding client crypto and fiat. The dual-asset nature of the custody function triggers both VASP/CASP obligations and, for the fiat component, payment services obligations. The structure question is whether to hold both licences within a single entity or to separate the custody and payment functions across related entities. Both approaches are used in practice. The entity split has capital and operational cost advantages; the single-entity approach simplifies client onboarding. We have seen regulators in more than one jurisdiction request detailed justification for either approach during the authorization review. The decision should be documented before the application is filed, not after questions arise.

Common Mistakes in Safeguarding Implementation

The mistakes we see most frequently are structural, not incidental. They are also preventable with the right analysis before the licence is granted rather than after the first supervision visit.

The first and most common is treating safeguarding as a documentation exercise rather than an operational one. A firm that has a safeguarding policy but has not confirmed with its bank that the account is held on segregated terms – in writing, with clear language about insolvency treatment – has a policy gap, not a safeguarding structure. Regulators will find that gap.

The second is failing to plan for banking relationship failure. A bank that closes a crypto company account without notice – which, as discussed above, is a documented risk – leaves the firm without a safeguarding vehicle. If the firm has only one banking relationship, client funds become unprotected at the moment the account closes. Best practice is a documented contingency – a second eligible institution identified in the safeguarding policy, with a process for transferring client funds within a defined window.

The third is structuring the entity without considering where safeguarding obligations arise. An offshore holding company that funnels client fiat through a subsidiary may create a situation where the subsidiary triggers payment services regulation in a market it did not intend to enter. That triggers safeguarding obligations the structure was not designed to satisfy. We map those exposure points as part of the structuring engagement.

A fourth mistake, specific to the cross-border context, is assuming that safeguarding compliance in the home jurisdiction satisfies the requirements of the client's jurisdiction. A Singapore-licensed DPT service provider serving EU institutional clients will need to address EU expectations on client money handling – not because MAS requires it, but because the EU institutional client's own compliance framework may require it as a condition of the relationship. Institutional clients increasingly run their own due diligence on the safeguarding structures of their counterparties.

Self-Assessment: Is Your Safeguarding Structure Sound?

The following questions reflect the areas a regulator will examine. A "no" or "uncertain" answer to any of them is a structural gap that warrants immediate attention.

  • Does your firm hold a payment institution or EMI licence in every jurisdiction where it receives and holds client fiat? If not, is an EMI arrangement in place that covers those activities?
  • Is client money held in a separately titled account at an eligible credit institution, with a written acknowledgment of segregated status from the bank?
  • Is there a documented, functioning day-end reconciliation process with a clear escalation path for discrepancies?
  • Does the safeguarding policy identify at least one alternative eligible institution as a contingency in the event of banking relationship failure?
  • Has the safeguarding policy been reviewed within the last twelve months, and does it reflect any changes to the licence, the business model, or the banking relationships?
  • For multi-currency operations: is there a separate safeguarding analysis for each currency corridor and each banking jurisdiction?
  • For businesses using covered assets: have eligible assets, concentration limits and mark-to-market monitoring been documented and tested?
  • Is the Travel Rule data infrastructure in place for cross-border virtual asset transfers, consistent with the FATF baseline and the specific requirements of each operating jurisdiction?

A firm that can answer "yes" with evidence to each of the above has a defensible safeguarding structure. A firm that cannot is carrying regulatory exposure that compounds over time.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close digital-asset company accounts primarily because of a mismatch between the firm's risk profile and the bank's AML/CFT obligations under frameworks like FATF Recommendation 15. The trigger is typically a change in the bank's own risk appetite, an inadequate response to an enhanced due diligence request, or a transaction pattern inconsistent with the profile on file. Proactive disclosure of the business model, AML controls and transaction flows – before the bank asks – materially reduces this risk. A structured pre-emptive engagement package is more effective than reactive remediation.

How can a VASP onboard with an EMI?

A VASP seeking to onboard with a licensed EMI must satisfy the EMI's own compliance requirements as a business client. That means providing detailed entity documentation, AML/KYC policies, beneficial ownership disclosure, a clear business model description mapped to the EMI's regulatory permissions, and evidence of licensing or registration in operating jurisdictions. EMIs may also conduct a site visit or request independent compliance certifications. The submission package should be prepared with the EMI's specific risk parameters in mind. Stalled applications typically fail on business model clarity or AML documentation gaps, both of which are addressable with preparation.

What does client-money safeguarding require?

Under the leading payment services regimes – EU, UK, Singapore and others – client-money safeguarding requires a licensed firm to hold client balances in a segregated account at an eligible credit institution, obtain a written acknowledgment of segregated status from the bank, maintain a documented day-end reconciliation process, and report to the regulator at prescribed intervals. The client funds must be legally insulated from the firm's own assets and from the firm's general creditors in the event of insolvency. The specific eligible assets, reporting formats and concentration limits vary by jurisdiction and licence category.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and we work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications where recovery is at issue. To discuss your situation, contact info@oboluslaw.com.

Speak with OBOLUS about your safeguarding structure. For a scoped assessment of your payment licence, EMI relationship and client funds structure, contact OBOLUS at info@oboluslaw.com or message us via t.me/oboluslaw. Map your options

By Victor Olsen, Regulatory & Compliance Analyst – specializing in payment services authorization, safeguarding compliance and AML/CFT frameworks for digital-asset businesses across the EU, UK and major licensing hubs.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours