Operating a regulated digital-asset business without a compliant client-funds safeguarding structure exposes the entity to enforcement, frozen payment rails and, ultimately, loss of the banking relationships that keep the business alive. Regulators across the major hubs – from MiCA and the VARA (Virtual Assets Regulatory Authority) regime in Dubai to the Payment Services Act in Singapore – are tightening their expectations around how client money is held, segregated and protected. The question is not whether safeguarding rules apply to your business; the question is whether your current structure actually meets them across every jurisdiction where you operate.
Client-funds safeguarding for regulated entities means the legal and operational requirement to hold client money separate from the firm's own assets, in a manner that ensures those funds are available to clients even in the event of the firm's insolvency. The requirement applies across payment institutions, EMIs (electronic money institutions), VASPs (virtual asset service providers) and, increasingly, crypto-asset service providers authorised under MiCA. Getting it wrong – even unintentionally – is one of the most common reasons regulators suspend activity and banks terminate accounts.
This page maps the regulated basis for safeguarding obligations, the methods available, the cross-border complications that catch businesses off guard, and how we structure the analysis for digital-asset operators building or defending their payment infrastructure.
Why client-funds safeguarding is a live enforcement risk for digital-asset businesses
Safeguarding failures sit at the top of the enforcement agenda for payment regulators in every major hub. Regulators do not treat non-compliance as a technical deficiency to be corrected over time; they treat it as a reason to restrict or revoke authorisation. For a digital-asset business, authorisation loss typically cascades: the banking partner reviews its risk exposure, the payment rail provider exits, and the business loses fiat access in days.
In our practice, the pattern is consistent. A business obtains a payment institution or EMI authorisation, sets up a segregated client account, and then – as the business scales – allows operational practices to diverge from the letter of the safeguarding requirement. Funds move between accounts for liquidity management. The reconciliation cadence slips. The safeguarding method drifts from the one disclosed to the regulator. By the time an audit or a banking review surfaces the issue, the gap has become material.
The risk is not hypothetical. Payment regulators in the EU, the UK and Singapore have each taken public action against entities that held client funds in arrangements that did not meet the applicable standard. The FCA's supervisory focus on safeguarding has intensified since its broader review of the payment sector. Under MiCA, ESMA and national competent authorities carry equivalent supervisory authority over CASPs handling client assets. Operators we advise routinely underestimate how quickly a safeguarding deficiency translates from an operational issue into a regulatory and banking crisis.
For a scoped safeguarding compliance review, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base geography and the banking relationships – change the analysis materially. Map your options
What is the regulated basis for client-funds safeguarding?
The legal obligation to safeguard client funds flows from the authorisation conditions attached to each regulated status – not from a single global standard. The payment institution and EMI regimes across the EU (under the applicable payment services directives, now transitioning under revised frameworks), the UK (under FCA rules), Singapore (under the Payment Services Act administered by MAS) and the UAE (under VARA and FSRA rules within ADGM) each impose their own safeguarding standard. The content overlaps significantly, but the method, timing and documentation requirements differ.
Under the EU regime, an authorised payment institution or EMI must safeguard client funds received against the risk of insolvency. The two main methods are segregation in a dedicated account with a credit institution, or coverage by an insurance policy or bank guarantee. The choice of method must be disclosed to the regulator at authorisation. Switching methods post-authorisation requires regulatory notification. Under MiCA, CASPs holding client crypto-assets face analogous requirements around segregation of client assets from the firm's own assets, with the expectation that this extends to the on-chain custodial layer.
In the UK, the FCA imposes safeguarding obligations on authorised payment institutions and registered EMIs under the applicable regulations. The FCA has published detailed expectations, including the requirement for a reconciliation process that can demonstrate the adequacy of safeguarded funds on a daily basis. In Singapore, the MAS Payment Services Act framework requires Major Payment Institution licensees holding customer funds to comply with specific safeguarding rules; Standard Payment Institutions face a lower threshold but are not exempt. VARA in Dubai addresses client-asset protection through its activity-specific rulebooks, with custody and exchange activities carrying the most prescriptive requirements.
The cross-border dimension matters immediately. A business authorised in one EU member state that passports its services across the EU/EEA under a MiCA CASP authorisation carries the safeguarding obligations of its home-state regulator – but must also manage the practical reality of banking relationships in multiple jurisdictions and, increasingly, the supervisory expectations of host-state regulators for material activity in their markets.
What are the three main safeguarding methods, and which applies to your structure?
The three principal methods for meeting safeguarding obligations are segregation in a designated client account, coverage by an insurance policy or guarantee, and – for certain asset types – investment in high-quality liquid assets. Each method has a different risk profile, a different cost structure, and a different relationship with your banking partner.
Segregation in a designated account is the most common approach. The entity opens a dedicated account at a credit institution, labels it as a client-funds account, and ensures the account holds only funds belonging to clients. The banking partner must acknowledge in writing that the funds are held on trust (or equivalent in civil-law systems) and are not available to satisfy the firm's creditors. Obtaining that acknowledgment is not always straightforward. Banks that are already cautious about digital-asset businesses are often reluctant to execute a formal safeguarding acknowledgment, because doing so creates a legal obligation on their side.
In our cross-border practice, we have seen businesses spend months obtaining the right banking structure in one jurisdiction only to find that their secondary banking partner in another jurisdiction is unwilling to replicate it. The result is a hybrid arrangement that satisfies neither regulator. Addressing this requires negotiating account terms with the bank directly, sometimes with legal support, before the authorisation application is submitted.
Insurance or guarantee coverage is less common in the digital-asset sector but has become more relevant as some banks have restricted access to designated accounts for VASPs and crypto-adjacent businesses. Where this route is available, the policy or guarantee must be from an appropriately rated insurer or bank, must cover the full value of client funds, and must be structured to pay out directly to clients (or a trustee on their behalf) in an insolvency scenario. Regulators scrutinise these arrangements carefully; a policy that only covers the firm's liability, rather than client funds directly, will not meet the standard.
Investment in liquid assets is available under certain regulatory regimes for specific asset classes, but the investment universe is narrow and the operational requirements are demanding. For most digital-asset businesses, this is not the first option to pursue.
How does the cross-border structure complicate safeguarding compliance?
For a business operating across multiple jurisdictions, the safeguarding requirement does not exist in isolation – it sits inside a stack of licensing, banking and operational decisions, and misalignment at any layer creates risk across all the others.
The most common structural problem we see is an entity that holds a licence in one jurisdiction, banks in another, and has users in a third. The licence imposes safeguarding obligations according to the home-state regulatory standard. The banking relationship is governed by the laws of the banking jurisdiction. The practical ability to segregate funds depends on what the bank will actually do. These three variables do not always point to the same outcome.
Consider a CASP authorised under MiCA through an EU member state. The MiCA regime imposes obligations at the EU level, implemented by the home-state national competent authority. The CASP may bank in a different EU member state – or, in many cases, with an EMI itself, creating a layered safeguarding question: how are funds safeguarded at the level of the EMI, and how does that interact with the CASP's own obligations to its clients? Regulators are increasingly asking this question directly during supervision.
A second structural complication arises where a business operates through multiple entities – a common structure for tax, licensing or liability reasons. Where one entity holds the licence and a separate entity holds the banking relationship, the question of which entity has the safeguarding obligation, and how that obligation is discharged across the group, requires a clear legal analysis before regulators or auditors ask for it.
In our practice, the cross-border analysis also extends to the choice of insolvency jurisdiction. Where client funds are held on trust, the enforceability of that trust in a cross-border insolvency depends on the law of the jurisdiction where the account is held. A trust under English law over an account in a civil-law jurisdiction may not be recognised in the way the firm expects. Operators we advise are typically surprised by how much the banking jurisdiction matters to the legal integrity of the safeguarding structure.
If your safeguarding structure crosses jurisdictions and you have not had it reviewed recently, write to OBOLUS at info@oboluslaw.com. If a prior application stalled or a banking partner pushed back on executing a safeguarding acknowledgment, a second read can surface the structural reason and the route forward. Map your options
What are the most common safeguarding mistakes regulated entities make?
The most frequent safeguarding failure is not an outright refusal to comply – it is a drift from the disclosed method as the business grows. Here are the patterns we see most often.
Using the wrong account type. A safeguarding account must be designated as such, and the bank must acknowledge it. General business accounts – even if labelled internally as "client" – do not meet the requirement in most regimes. The acknowledgment from the bank is not a courtesy; it is a legal prerequisite. Many businesses use accounts that have never been formally acknowledged, either because the bank declined to give the acknowledgment or because the question was never put to the bank.
Failing to reconcile in time. Most regulatory regimes require that the entity be able to demonstrate, at any point, that the safeguarded funds are adequate. In practice, this means a daily reconciliation process between the balance of client liabilities and the balance in the safeguarding account. Businesses that do this weekly or on an ad hoc basis are running a persistent compliance gap. Regulators treat inadequate reconciliation as evidence of a structural failure, not an administrative oversight.
Mixing business and client funds intraday. Liquidity management often leads to intraday transfers between operational and client accounts. Some regulatory regimes prohibit this entirely. Others permit it only within defined parameters. Businesses that use client accounts as a buffer for their own treasury operations are almost always non-compliant, regardless of how quickly they rebalance.
Not updating the safeguarding method after a banking change. If a business changes its safeguarding bank – because the original bank de-risked the account – and does not notify the regulator, the entity is operating outside its authorisation conditions. De-risking events therefore trigger a regulatory notification obligation, which many businesses are unaware of at the time the account is closed.
Ignoring the crypto-asset layer. Under MiCA and equivalent regimes, the safeguarding obligation extends to crypto-assets held on behalf of clients. This is not the same as holding fiat. The technical infrastructure – whether the entity uses hot or cold wallets, whether assets are held by a sub-custodian, and whether client assets can be identified on-chain in an insolvency – is part of the regulatory assessment. Businesses that have strong fiat safeguarding and weak on-chain segregation are creating an asymmetric risk profile.
Which safeguarding structure fits your operator profile?
The right safeguarding method depends on the nature of the business, the jurisdictions in operation and the banking relationships available. What follows is a practical framework – not a legal recommendation – for thinking through the options.
Profile A: EU/EEA-authorised payment institution or CASP banking with a tier-one credit institution. The standard approach is a designated safeguarding account with a formal trust acknowledgment from the bank. The timeline to establish this arrangement, once a willing bank is identified, is typically a matter of weeks from the point of account negotiation. The key risk is bank reluctance to execute the acknowledgment for crypto-adjacent businesses. Legal support in the negotiation materially improves the outcome.
Profile B: VASP or payment institution banking with an EMI rather than a credit institution. The regulatory position in several jurisdictions is that safeguarding through an EMI account may be permissible, but only if the EMI itself meets the safeguarding standard for the funds it holds. This creates a layered analysis: the entity must satisfy itself (and its regulator) that the EMI's own safeguarding structure is adequate. This requires due diligence on the EMI's regulatory status and safeguarding arrangements – not just an account opening process.
Profile C: Multi-jurisdictional group with a central licensing entity and operational entities in multiple markets. A group structure requires a consolidation of the safeguarding analysis. Each licensed entity in the group has its own obligation. Where entities share banking infrastructure, the allocation of client funds between entities and accounts must be traceable. The group's consolidated safeguarding position should be documented and reviewed regularly. The cross-border insolvency question – which jurisdiction's insolvency law governs the trust – needs a specific legal assessment, not a generic assumption.
Profile D: New market entrant seeking authorisation and banking simultaneously. This is the hardest profile to manage. Banks typically require a licence before opening a safeguarding account; regulators typically expect a safeguarding bank to be in place before granting a licence. The practical solution is to engage a banking partner (or EMI) that is prepared to issue a conditional account commitment, and to present that commitment to the regulator as part of the authorisation application. We map this sequence for clients early in the authorisation process, because starting it late adds months to the timeline.
How we have approached this in practice
In a recent matter, a payments company with a European payment institution authorisation was notified by its safeguarding bank that its account would be closed as part of a broader de-risking exercise. The notice period was short. The company faced a regulatory obligation to notify its home-state regulator of the change and to establish a replacement safeguarding arrangement before the existing account closed. We worked with the company to identify a replacement banking partner, to draft the regulatory notification in the required form, and to negotiate the trust acknowledgment with the replacement institution. The replacement account was operational and the regulatory notification was filed within the required window. The company retained its authorisation without interruption.
In a separate matter handled earlier in the year, a custody service provider expanding from a VARA-regulated Dubai structure into the EU encountered a safeguarding gap: its Dubai structure met VARA's client-asset protection requirements, but the proposed EU vehicle did not have a safeguarding method that would satisfy the home-state national competent authority for its MiCA CASP application. We mapped the differences between the VARA framework and the MiCA regime, identified the structural change required, and worked with allied counsel in the relevant EU jurisdiction to implement it ahead of the application filing. The application was submitted with a compliant safeguarding structure from the outset.
A common assumption: one offshore licence covers global operations
A common assumption among earlier-stage digital-asset businesses is that a single licence – often obtained in a well-regarded offshore jurisdiction – is sufficient to serve clients globally, including for the purpose of meeting client-funds safeguarding obligations in each market where users are located. This is incorrect in almost every case.
Safeguarding obligations attach to regulated activities in the jurisdiction where those activities are performed or where the client is located, not solely to the jurisdiction of the licence. A business operating under a BVI VASP Act registration that serves EU users may face safeguarding expectations from EU regulators under MiCA's third-country provisions, even though it holds no EU authorisation. Similarly, a business licensed in one EU member state that fails to implement the safeguarding standard of that state – even if it believes a more permissive regime applies – is in breach of its authorisation conditions.
The practical consequence is that operating with a single jurisdiction's licence while serving users in multiple markets creates a gap between the licences held and the regulatory expectations applicable to actual operations. We map the licence stack across the operating, custody and payment layers before clients commit to a structure – because identifying the gap at the design stage is significantly less costly than addressing it after enforcement contact.
Related at OBOLUS
- Banking, Payments & EMI Onboarding for Digital-Asset Businesses – the full practice overview covering fiat rails, EMI selection and cross-border banking strategy
- De-Risking and Account Closure Defence – defending against bank account termination and rebuilding payment infrastructure after de-risking
- Client Funds Safeguarding for Established Operators – safeguarding reviews and remediation for businesses already in operation
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because of perceived AML/CFT risk, regulatory uncertainty about the legal status of the account holder's activities, and compliance cost. Correspondent banking exposure, internal risk appetite policies and, in some cases, pressure from the bank's own regulator all contribute. The trigger is often a business change – a new product, a new jurisdiction, a new licence status – that prompts the bank to re-evaluate the relationship. Having the right legal structure and clear documentation of the business model materially reduces this risk.
How can a VASP onboard with an EMI?
A VASP seeking to onboard with an EMI (electronic money institution) must typically demonstrate that it holds the appropriate licence for its activities, that it has adequate AML/KYC procedures, and that its business model is consistent with the EMI's own regulatory permissions. The EMI's compliance team will conduct due diligence on the VASP's regulatory status, its transaction volumes and its source-of-funds position. Presenting a complete regulatory and compliance file at the outset – rather than responding to repeated information requests – significantly shortens the onboarding timeline.
What does client-money safeguarding require?
Client-money safeguarding requires a regulated entity to hold client funds separately from its own assets, in a manner that protects those funds in the event of the firm's insolvency. The specific requirements – the method of segregation, the timing of reconciliation, the documentation required – vary by jurisdiction and by the type of authorisation held. Under MiCA, the obligation extends to crypto-assets held on behalf of clients, not just fiat. The starting point is identifying the applicable regime for each entity in the group and mapping the current structure against its requirements.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence, banking and safeguarding stack across the operating, custody and payment layers before clients commit to a structure – because getting this right at the design stage is what protects the business when regulators or banking partners ask the hard questions. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP and payment institution authorisation, safeguarding compliance and cross-border regulatory structuring for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.