EST · MMXXVI
Home/Services/Banking Payments Emi/Client funds safeguarding: Legal Counsel for Digital-Asset Firms
Banking, Payments & EMI Onboarding

Client funds safeguarding: Legal Counsel for Digital-Asset Firms

Client funds safeguarding: Legal Counsel for Digital-Asset Firms. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. T

Operating a digital-asset business without a properly structured client-funds regime is not a compliance gap – it is an existential risk. Banks flag unprotected pools as undifferentiated principal money. Regulators in every major hub now expect segregation, reconciliation and, in most cases, a qualifying custodian or ring-fenced account before they approve an operating licence. A single structural error at the payment layer can freeze every fiat rail the business depends on overnight.

Client funds safeguarding: legal counsel for digital-asset firms addresses the full regulated perimeter: the applicable payment or EMI (electronic money institution) licence, the segregation mechanics required under the relevant regime, the banking and EMI onboarding process, and the cross-border interactions that arise when entity, users and fiat rails sit in different jurisdictions. At OBOLUS we structure the licence stack, the account architecture and the compliance documentation as one mandate – not as sequential work items that later contradict each other.

This page sets out the regulated basis for client-money protection, the typical process steps, common structural mistakes, and the cross-border considerations that determine which safeguarding model your business actually needs.

What Is the Regulated Basis for Client Funds Safeguarding?

Client funds safeguarding in the digital-asset context is the obligation to hold client money or e-money in a manner that protects it from the insolvency of the firm and from misappropriation. The requirement does not arise from any single rule set. It emerges from the intersection of three overlapping regimes: the payment licence or EMI authorisation in the firm's home jurisdiction, the VASP (virtual asset service provider) licence conditions imposed by the relevant crypto regulator, and – in most operating models – the account terms imposed by the correspondent bank or EMI partner.

Under MiCA – the EU's Markets in Crypto-Assets Regulation supervised by ESMA and national competent authorities – CASP authorisation (Crypto-Asset Service Provider) comes with explicit client-asset protection conditions. Custody CASPs must segregate client crypto assets and may not use them for proprietary purposes. Where a CASP also handles fiat flows, the applicable payment services regime in the member state stacks on top: an EMT (e-money token) issuer must comply with the e-money authorisation requirements, including a ring-fenced asset pool. MiCA passporting means a single CASP authorisation can cover the EU/EEA, but the safeguarding mechanics apply from day one in the authorising member state.

In Dubai, VARA (the Virtual Assets Regulatory Authority) imposes safeguarding conditions through its activity-specific rulebooks. A licensed exchange or custodian must maintain client assets in segregated accounts, and the fiat component requires a relationship with a regulated financial institution that acknowledges the segregated nature of the account. In practice, VARA-licensed firms onboard with licensed payment institutions or banks that operate in the UAE or via correspondent arrangements, a process that raises its own set of structural questions.

Beyond Dubai, the ADGM (Abu Dhabi Global Market) and its FSRA (Financial Services Regulatory Authority) apply a comparable custody and safeguarding framework for recognised virtual assets. Singapore's MAS (Monetary Authority of Singapore) imposes customer-money protection rules under the Payment Services Act for DPT (digital payment token) service licensees. The FCA in the United Kingdom imposes safeguarding requirements on EMIs under the applicable money regulations. Every major hub has a version of the same principle; the variation is in the mechanics, the qualifying asset categories and the approved custodian lists.

Why Does a Payment Licence Matter for a Crypto Business?

A crypto business that touches fiat – accepting client deposits, settling withdrawals, holding user balances in currency – is almost certainly carrying on a regulated payment activity, regardless of its crypto licence status. The two licences address different things and the absence of the payment layer creates a gap that banks treat as a red flag.

In our cross-border practice, we regularly see exchanges and custodians that obtained a VASP registration quickly and then discovered their banking applications were declined because the account would hold client fiat without a qualifying payment institution or EMI licence. The bank's compliance team, applying its own de-risking policy, sees an unprotected client-money pool and declines.

The crypto banking relationship is therefore not simply a matter of finding an institution willing to open an account. It requires presenting a complete regulatory picture: the VASP or CASP licence, the payment or EMI authorisation, the safeguarding policy document, the account segregation evidence and – increasingly – a third-party reconciliation attestation. Banks and EMIs that service the digital-asset sector have become more structured in their onboarding requirements, not less.

A common structural mistake at this stage is relying on a single EMI partner for both the safeguarding account and the payment settlement account. That concentration risk is now scrutinised by regulators and by sophisticated banking partners. The stronger architecture separates the safeguarding pool from the operating account, with each held at a different institution where feasible.

For a scoped assessment of your current payment and safeguarding architecture, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options.

How Does EMI Onboarding Work for a Digital-Asset Firm?

EMI onboarding for a digital-asset business follows a structured due diligence sequence that is materially more demanding than standard corporate account opening, and the process varies significantly depending on whether the EMI is regulated under MiCA-adjacent rules, the FCA regime, MAS requirements or another framework.

The typical process has four stages. First, the firm prepares a pre-application pack: the regulatory licences held, the AML/KYC programme documentation, the beneficial ownership register, the business model description addressing the token categories handled, the safeguarding policy and the projected transaction volumes. This pack is submitted for an initial eligibility review. Most EMIs will not proceed to a formal application without a positive eligibility signal.

Second, the EMI conducts its own enhanced due diligence on the applicant entity. At this stage, the quality of the firm's AML documentation – its policies, its independent audit, its Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer) compliance posture – is determinative. EMIs that have been examined by their regulator on their crypto-client book are now applying the same level of scrutiny as a correspondent bank would.

Third, account structuring is agreed. This includes the currency accounts to be opened, the safeguarding account designation, limits, settlement cycles and the conditions under which the EMI may apply a hold. This is a negotiated document, not a standard-form take-it-or-leave-it, and the terms agreed at this stage have direct operational implications for how the firm can structure client withdrawals and redemptions.

Fourth, the ongoing compliance obligations are confirmed: periodic reporting to the EMI, notification triggers for material changes to the business, and the conditions under which the EMI may terminate or restrict the account. In our practice, we advise clients to treat the EMI relationship agreement as a regulated contract, not as a standard bank mandate, because the termination provisions can expose the firm to exactly the frozen-rail risk that a well-structured payment layer is meant to prevent.

Indicatively, the process from initial eligibility submission to account activation takes a matter of weeks to a few months depending on the completeness of the pre-application pack and the EMI's own queue. A firm that submits incomplete AML documentation at the first stage typically loses weeks to a remediation cycle it could have avoided with proper preparation.

What Are the Most Common Safeguarding Mistakes in Digital-Asset Firms?

The most common mistake is treating safeguarding as an account-type question rather than a regulatory question. Firms open a separate bank account, label it "client funds," and consider the obligation discharged. In fact, the regulated obligation requires the account to be formally designated as a safeguarding account with the relevant bank or EMI acknowledging that designation in writing, and the account to be subject to daily reconciliation against the firm's client-money ledger.

The second recurring error is commingling the safeguarding pool with operating capital during the period between a client deposit arriving and its recording on the ledger. Even a brief technical delay in ledger entry can create a commingling event that the firm's auditor will flag and that the regulator will treat as a breach.

A third structural gap we encounter frequently is the absence of a written safeguarding policy that addresses both the fiat and the crypto dimensions. Regulators in the leading hubs increasingly expect a single consolidated safeguarding document that maps every client-asset category – fiat, stablecoins, other tokens – to the segregation mechanism and the insolvency treatment. A firm that has a fiat safeguarding policy but no corresponding crypto-custody policy has an incomplete regime.

Finally, the cross-border firms we advise routinely encounter the jurisdictional mismatch problem. A firm licensed in one EU member state and serving users across several others may have its safeguarding accounts held in a third jurisdiction where the bank is located. The insolvency treatment of those accounts in the event of bank failure is governed by the law of the account location, not by the firm's home regulator's rules. That analysis has to be done in advance, not after an insolvency event.

What Cross-Border Issues Affect Client Funds Safeguarding?

The cross-border dimension of client funds safeguarding is the issue that most mid-sized digital-asset businesses underestimate. A business can be licensed in Lithuania under the MiCA transition framework, hold its safeguarding accounts with an EMI based in the United Kingdom regulated by the FCA, and serve users whose deposits originate from payments processed through a PSP (payment service provider) in Georgia or a correspondent bank in Singapore. Each link in that chain has its own legal character.

The most immediate question is the priority of the safeguarding account in insolvency. English law and MiCA member-state law both provide for enhanced creditor priority for designated safeguarding accounts. But the legal effect depends on the account agreement properly establishing the trust or segregation structure, and on the bank or EMI having acknowledged that structure in its records. Where the account-holding institution is in a third country, the question is whether that country's insolvency law recognises the priority claim. This is not a hypothetical: it is the operative question in every cross-border payment architecture.

The Travel Rule adds a second layer of cross-border complexity. Under FATF Recommendation 15 and its implementing rules across the major hubs, a VASP transferring virtual assets must pass originator and beneficiary data to the receiving institution. Where the receiving institution is a bank or EMI that is not a VASP, the data transmission requirements create a gap that the firm's compliance architecture must bridge. In our cross-border practice, we work with operators to map the Travel Rule flows across every corridor in their payment architecture before the account is live.

In a recent matter, a payments company operating under an EU-based CASP authorisation needed to route client-fund flows through an EMI in a non-EU jurisdiction. We worked with allied counsel in the relevant jurisdiction to map the account designation requirements, the insolvency priority position and the Travel Rule obligations. The result was a complete payment-layer opinion that the client's CASP regulator accepted as part of the ongoing supervisory review.

If your payment architecture spans multiple jurisdictions and you need a cross-border assessment, write to OBOLUS at info@oboluslaw.com. If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Map your options.

Which Safeguarding Structure Fits Your Business Profile?

The right safeguarding architecture depends on the firm's licence type, the asset categories it handles, its operating jurisdictions and the volume profile of its client flows. A single model does not serve every digital-asset business.

Profile A – EU-licensed exchange handling fiat and crypto: The appropriate structure is a CASP authorisation in a qualifying EU member state (with MiCA passporting), a domestic or cross-border EMI or payment institution for the fiat layer, segregated safeguarding accounts in each currency formally acknowledged by the account-holding institution, and a daily reconciliation process. The primary risk is the MiCA transition timeline: firms operating under legacy VASP registrations need to align their safeguarding regime with the CASP requirements on the applicable transition timetable. Timeline to full compliance from a standing start: typically several months, varying by member state and preparedness.

Profile B – VARA-licensed exchange in Dubai: The VARA rulebook sets specific requirements for the fiat safeguarding account, which must be held at a regulated financial institution. The primary risk for an inbound operator is the banking relationship: not all UAE banks will open accounts for crypto firms, and the VARA licence alone does not guarantee banking access. The firm needs to demonstrate a qualifying banking relationship before VARA approves full operational status. The cross-border complexity arises where the firm also services non-UAE users – at that point the user's home-jurisdiction rules stack on top.

Profile C – Offshore-registered custodian serving institutional clients: A BVI FSC or Cayman CIMA registration under the applicable VASP Acts creates a baseline AML/VASP compliance framework but does not substitute for a payment licence if the firm is holding fiat client money. An offshore custodian taking in fiat deposits – even temporarily in settlement cycles – needs a qualifying payment or e-money authorisation in a regulated hub if it is to onboard with institutional-grade banking partners. A common assumption is that an offshore registration is sufficient for global operations; it is not, and the banking due diligence process will surface that gap.

Profile D – Payments company adding crypto settlement: A firm that is already licensed as a payment institution or EMI and wants to add crypto settlement to its product set is entering regulated VASP territory. Most payment regulators now expect a notification or a variation of the existing authorisation, and the safeguarding policy must be updated to address the crypto-asset dimension. The risk is that the firm's existing safeguarding account agreements do not contemplate crypto assets and need to be renegotiated or supplemented.

What Does OBOLUS Do in a Client Funds Safeguarding Mandate?

In a client funds safeguarding mandate, OBOLUS maps the full licence and account structure before the firm commits to an architecture it may need to unwind at cost. Our work typically covers four deliverables.

First, a regulatory mapping opinion that identifies every jurisdiction in which the firm's payment activity triggers a licence requirement, maps the applicable safeguarding obligation in each, and identifies gaps in the current structure. This is the document that a GC sends to the board before the next funding round.

Second, pre-application preparation for the relevant payment or EMI licence or for the VASP/CASP licence variation that covers client-money activity. We draft the AML/KYC programme documentation, the safeguarding policy, the business-model description and the account-structure diagram to the standard that the leading regulators expect. In our practice, we have seen incomplete pre-application packs lose months to remediation cycles; we run the regulatory quality check before submission.

Third, EMI and banking onboarding support. We work alongside the firm through the EMI due diligence process – preparing the eligibility pack, reviewing the account agreement terms (particularly the safeguarding account designation, the termination provisions and the Travel Rule data-sharing obligations), and negotiating the account structure where the EMI's standard terms do not reflect the firm's operating model.

Fourth, ongoing compliance architecture. We structure the reconciliation framework, the commingling controls and the cross-border insolvency analysis as documents the firm's compliance team can operate, not as a one-off opinion that sits in a file. We map the licence, banking and tax stack across operating, custody and payment layers before the firm commits.

Self-Assessment: Is Your Safeguarding Structure Complete?

The following indicators are not exhaustive, but a "no" answer to any of them warrants immediate legal review.

  • Does the firm hold a payment licence or EMI authorisation that covers the fiat client-money activity it currently carries on?
  • Is every safeguarding account formally designated as such in a written acknowledgment from the account-holding institution?
  • Does the firm's AML/KYC programme specifically address virtual asset transfers and Travel Rule obligations?
  • Has the insolvency priority of the safeguarding accounts been analysed under the law of the account-holding jurisdiction?
  • Does the firm have a single consolidated safeguarding policy that addresses both the fiat and the crypto-asset dimensions?
  • Has the firm obtained written confirmation from its banking or EMI partner that commingling controls are acknowledged?

Operators we advise routinely discover during this checklist exercise that they have a partial safeguarding structure that worked at an earlier stage of the business but does not meet the current regulatory expectation. The gap is almost always discovered either at the next licence renewal, at a banking due diligence event or – in the worst case – at an enforcement inquiry. Early identification is structurally cheaper than remediation under regulatory pressure.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily because of de-risking policy, not because the activity is unlawful. A bank's compliance team evaluates the crypto firm's licence status, its AML programme, its client-money architecture and its transaction volume profile. Where any of those elements is incomplete or undocumented, the bank's own regulatory risk – particularly under anti-money-laundering examination – outweighs the commercial relationship. A firm presenting a complete regulatory picture, including a qualifying payment licence, a formal safeguarding structure and a documented Travel Rule compliance posture, is materially more bankable than one relying on a VASP registration alone.

How can a VASP onboard with an EMI?

An EMI onboarding for a VASP begins with an eligibility submission: the firm's licence documents, its AML/KYC programme, beneficial ownership register, business model description and safeguarding policy. The EMI conducts enhanced due diligence on that pack before proceeding to a formal application. The key determinants of a successful onboarding are the completeness of the AML documentation, the clarity of the business model and the firm's Travel Rule compliance posture. A well-prepared eligibility submission typically reduces the overall onboarding timeline significantly compared with an ad hoc approach.

What does client-money safeguarding require?

Client-money safeguarding requires, at a minimum, three elements: a formally designated account at a regulated institution with written acknowledgment that the account holds client money on a segregated basis; a daily reconciliation process that matches the account balance to the client-money ledger; and a written safeguarding policy that covers every asset category the firm holds on behalf of clients, including both fiat and crypto assets. In most regulated regimes, the firm must also demonstrate that its safeguarding accounts would be treated as protected assets in the firm's insolvency – which requires an account designation opinion and, for cross-border architectures, a conflict-of-laws analysis.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit, and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in payment licensing, EMI onboarding and client-money regulatory frameworks for digital-asset businesses across EU, UAE and offshore jurisdictions.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours