EST · MMXXVI
Home/Services/Banking Payments Emi/Client funds safeguarding under Heightened Scrutiny
Banking, Payments & EMI Onboarding

Client funds safeguarding under Heightened Scrutiny

Client funds safeguarding under Heightened Scrutiny. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS

Client funds safeguarding under heightened scrutiny sits at the intersection of payment regulation, AML/CFT compliance and banking-relationship management — three disciplines that most digital-asset operators treat as separate problems until a correspondent bank closes the account or a regulator questions whether client money is genuinely ringfenced. For any business holding fiat on behalf of clients — an exchange, a custodian, a payments firm operating under a payment institution licence (an authorisation to initiate, execute or transmit funds on behalf of third parties) — the safeguarding question is never purely academic. It is the condition on which the banking relationship, the licence and, ultimately, client trust depend.

The regulatory basis for safeguarding is settled across the leading payment regimes: client funds must be held separately from operating capital, in a qualifying account or invested in specified liquid assets, and must be identifiable as belonging to clients at all times. The specifics — which account types qualify, what documentation the bank needs, how long a firm may hold funds before safeguarding obligations attach — vary by regime. What does not vary is the direction of travel: regulators in every major hub are tightening their expectations, and banks serving licensed payment firms are under parallel pressure from their own prudential supervisors to verify that safeguarding arrangements are genuinely in place.

This page maps the regulated basis, the practical process, the cross-border complications and the most common structural errors that OBOLUS sees when advising digital-asset businesses on their fiat-rail and payment-licence architecture.

Why safeguarding is a live risk, not a compliance formality

Heightened scrutiny of client funds is not a new concept in payments regulation, but the intensity of supervisory focus on digital-asset businesses has increased sharply as regulators apply existing payment-regulation obligations to crypto-facing firms at scale. The FCA in the United Kingdom, for example, has made safeguarding a standing examination priority for registered cryptoasset businesses and authorised payment institutions alike, issuing multi-firm review findings that identify inadequate segregation of client funds as one of the most frequent deficiencies. ESMA and the relevant national competent authorities under MiCA apply equivalent expectations to licensed crypto-asset service providers that handle client fiat.

The consequence of a safeguarding failure is not merely a regulatory censure. A deficiency finding can trigger account closure by the banking partner — which is typically the only entity in a position to verify that the segregated account is maintained correctly. Once a bank terminates the safeguarding account, the operator's fiat rails collapse. Recovery timelines are measured in weeks, not days, and the reputational damage to a firm serving institutional clients can be permanent.

In our practice, the firms most exposed are those that structured their banking in a jurisdiction of convenience — often chosen for speed of EMI onboarding rather than regulatory quality — and later discovered that the correspondent bank's compliance team could not reconcile the safeguarding arrangements with the firm's actual transaction profile.

The process above describes the standard path. Your facts — the entity, the user base, the banking — change the analysis. For a scoped assessment of your safeguarding structure and the banking relationships that support it, contact OBOLUS at info@oboluslaw.com or map your options.

What does the regulated basis for safeguarding actually require?

Safeguarding obligations attach the moment a licensed payment firm holds funds that belong to a client — they do not wait for the funds to be "in transit." The core requirement, consistent across the FCA regime, the EU Payment Services framework, MiCA's CASP provisions and equivalent rules in MAS-supervised entities, is segregation: client money must be separated from the firm's own money in a way that would allow it to be identified and returned to clients if the firm became insolvent.

Three structural elements follow from that requirement. First, the safeguarding account must be held with a credit institution or a qualifying custodian — not with a payment intermediary whose own regulatory status is unclear. Second, the account must be designated as a client-funds account in a way that is legally enforceable against a liquidator. Third, the firm must reconcile the balance of the safeguarding account against its own records of client balances on a regular basis, with written procedures governing what happens when a discrepancy arises.

The cross-border complication is this: a firm licensed in one jurisdiction may hold client funds in a bank account in a second jurisdiction, which bank account is governed by the insolvency law of a third jurisdiction. Whether a liquidator in any of those three jurisdictions would give effect to the contractual trust or statutory trust that the safeguarding regime is trying to create is not a question that the licensing authority answers — it is a question for local counsel in the jurisdiction of the bank account. OBOLUS maps that legal risk across all three layers as part of a safeguarding review.

How does EMI onboarding work for a digital-asset business?

EMI onboarding (the process by which a digital-asset business establishes a banking relationship with an authorised electronic money institution — an entity licensed to issue electronic money and provide associated payment services) has become the primary route to fiat rails for crypto operators that cannot obtain a direct banking relationship with a retail or commercial bank. The EMI acts as the conduit: it holds a segregated account at its own bank and issues a ledger entry — electronic money — to the client firm against that balance.

The practical consequence for safeguarding is a layered structure. The crypto firm does not hold client funds directly at a bank; the EMI does. The EMI's own safeguarding obligations protect the electronic money balance at the EMI level. But if the crypto firm is itself a licensed payment institution or a VASP (virtual asset service provider) with its own obligations to segregate client money, a second layer of safeguarding may apply — the firm's clients are owed the same protection against the firm's insolvency that the EMI's clients receive against the EMI's insolvency.

In our cross-border practice, we see this layering issue arise most frequently when a firm has incorporated in a jurisdiction with a permissive registration regime — the BVI, the Cayman Islands or a Seychelles-licensed payment institution — but is serving clients in the EU or UK, where both regulators and counterparty banks apply home-jurisdiction standards to the entire structure. The offshore licence does not exempt the firm from the safeguarding expectations of the jurisdiction in which the client or the bank is located.

The bank or EMI conducting its own due diligence will ask for evidence of the safeguarding structure, not merely evidence of the licence. A licence certificate and a corporate structure chart are rarely sufficient. The bank wants to see the legal opinion confirming enforceability of the trust designation, the reconciliation procedures and — increasingly — the AML/KYC policies governing the underlying transactions flowing through the account.

What are the most common safeguarding errors that attract regulatory scrutiny?

Most safeguarding failures are structural rather than fraudulent. They arise from decisions made during entity setup — decisions that were reasonable at the time but were not reviewed as the business scaled or as the regulatory environment changed. The following are the errors OBOLUS most frequently identifies in a pre-regulatory-exam review.

Commingling at the account level. The safeguarding account holds both client funds and funds that belong to the firm — fee income, operational reserves, intraday liquidity buffers. The distinction is maintained in the ledger but not at the bank-account level. Under most payment regimes, this is not compliant segregation. A bank's compliance team that reviews the account will identify the commingling and may report it to the regulator before informing the client firm.

Wrong account type or wrong jurisdiction. The safeguarding account is held with an entity that is not a qualifying credit institution in the jurisdiction whose law governs the account. Some firms have attempted to hold safeguarding balances at crypto-native custodians or at payment intermediaries that are themselves unlicensed. The qualifying-institution requirement is not negotiable in any of the leading regimes.

Inadequate reconciliation procedures. The firm reconciles client balances weekly or monthly. Under heightened-scrutiny conditions — which regulators in the FCA, MAS and VARA environments now apply to most digital-asset businesses — daily reconciliation is expected, with documented procedures for discrepancy resolution. A weekly reconciliation cycle means that, for most of the week, the firm cannot demonstrate that the safeguarding balance equals the aggregate client balance.

Undocumented trust designation. The account mandate held at the bank does not use trust language, or the letter of designation was not signed or filed at a time that would be effective against a liquidator. This is the most dangerous error because it is invisible in the day-to-day operation of the firm and only becomes material in an insolvency or a regulatory inspection.

How does a cross-border structure affect fiat-rail resilience?

A digital-asset business operating across multiple jurisdictions faces a fiat-rail problem that is not simply the sum of its individual licensing problems. The firm may be licensed in Lithuania under the Bank of Lithuania's VASP/CASP regime, banked through an EMI in the UK under FCA supervision and serving clients in the Gulf who wire fiat through a correspondent chain that touches a US clearing bank. Each link in that chain applies its own enhanced-due-diligence standard to the digital-asset counterparty, and each link can unilaterally terminate.

The US clearing banks are worth particular attention. FinCEN guidance and the correspondent-banking risk appetite of US financial institutions means that, in practice, any EUR or USD transaction involving a crypto-facing counterparty will be scrutinised at the US dollar clearing stage regardless of where the sending bank or the receiving firm is licensed. A firm that has done careful work on its EU or UK safeguarding structure may still find its fiat rails interrupted because its transactions do not pass a US correspondent bank's automated transaction-monitoring filters.

The Travel Rule — the FATF obligation to pass originator and beneficiary information with a virtual-asset transfer — adds another dimension. A firm that cannot demonstrate Travel Rule compliance to its banking partner is likely to see its account flagged as high-risk even where the safeguarding structure itself is sound. Banking partners increasingly treat Travel Rule compliance and safeguarding adequacy as a composite package in their enhanced-due-diligence review of crypto business clients.

Structural resilience requires, at minimum, two banking relationships in different jurisdictions and different currency jurisdictions, with each safeguarding structure reviewed by local counsel in the relevant account jurisdiction. We advise clients to treat banking redundancy as a core architectural requirement, not a contingency plan.

If a prior application stalled or an account was closed, a second structural read can surface the underlying reason and the route back. Write to OBOLUS at info@oboluslaw.com or map your options.

A practical illustration and a decision matrix by operator profile

In a recent matter, a licensed payments firm that had structured its fiat operations through an EMI in one EU member state found that its safeguarding account designation was unenforceable under the insolvency law of the jurisdiction where the underlying bank account was held — two jurisdictions removed from the issuing regulator. The trust language in the account mandate had been drafted by reference to the licensing-jurisdiction regime rather than the account-jurisdiction insolvency law. We reviewed the mandate, obtained a legal opinion in the account jurisdiction, and negotiated a revised account structure that satisfied both the regulator and the banking partner. The firm retained its fiat rails without interruption to client balances.

The decision matrix below sets out the typical analysis by operator profile.

Profile A — Licensed exchange, EU-regulated, serving EU and non-EU clients. The applicable regime is MiCA's CASP framework, supplemented by the EU Payment Services regime for fiat handling. The safeguarding obligation is layered: crypto-asset safekeeping rules apply to the digital-asset side; payment-regulation safeguarding rules apply to fiat balances held pending execution. The indicative complexity is high, and the principal risk is a mismatch between the regulator's expectation and the banking partner's interpretation of the safeguarding documentation.

Profile B — VASP registered offshore, serving global clients through an EMI. The offshore licence establishes the VASP's own regulatory status but does not supply a safeguarding framework that the EMI's regulator will recognise. The EMI's safeguarding structure protects against the EMI's insolvency; it does not protect the VASP's clients against the VASP's insolvency. A second-layer safeguarding structure, governed by the law of a jurisdiction whose insolvency rules support trust-based segregation, is required. The key risk is the assumption — common among offshore-incorporated firms — that the EMI's protections flow through to the end client.

Profile C — Payment institution or EMI seeking direct bank access. This profile requires the strongest safeguarding documentation: a designated trust account, a legal opinion on enforceability, daily reconciliation procedures, and a Board-approved safeguarding policy. The indicative timeline for a first banking relationship is a matter of several months; a second relationship, using the first as a reference, can proceed more quickly.

A common assumption that costs businesses their banking

A common assumption in the digital-asset sector is that a single offshore licence — issued by a permissive regulator, obtained quickly and at modest cost — is sufficient to underpin a global payments and safeguarding structure. It is not.

The offshore licence establishes that the firm has met the minimum threshold for registration in that jurisdiction. It says nothing about the adequacy of the safeguarding arrangement from the perspective of a bank in Frankfurt, London or Singapore conducting its own enhanced due diligence. Banks apply the standards of their own regulatory environment, not the licensing jurisdiction's standards, when deciding whether to open or maintain a safeguarding account for a digital-asset business client.

The firms that maintain stable banking relationships over time are those that have matched their safeguarding structure to the most demanding regulatory environment in which they operate — which is typically the jurisdiction of their banking partner, not the jurisdiction of their licence. OBOLUS maps that mismatch as the first step in any banking-engagement mandate.

Self-assessment: is your safeguarding structure sound?

The following indicators suggest a safeguarding structure that may not withstand heightened scrutiny. If any of these apply, a structural review is warranted before the next regulatory examination or banking due-diligence request.

  • The safeguarding account is held at an entity that is not a licensed credit institution in the jurisdiction whose insolvency law governs the account.
  • The account mandate does not include express trust language that is enforceable under the insolvency law of the account jurisdiction — not merely under the licensing jurisdiction's law.
  • Client balances are reconciled against the safeguarding account less frequently than daily.
  • The firm holds fee income, operational reserves or intraday liquidity in the same account as client funds, relying on a ledger distinction rather than physical segregation.
  • The firm has no written procedure for handling a safeguarding-account discrepancy, including escalation to the board and notification to the regulator.
  • The structure has not been reviewed by counsel in the jurisdiction of the bank account — only by counsel in the jurisdiction of the licence.
  • The firm has a single banking relationship with no backup fiat-rail structure.

These are the indicators that regulators and banking-relationship managers flag first. A structure that presents none of these weaknesses is not immune from heightened scrutiny, but it starts from a defensible position.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily because the business cannot demonstrate, to the bank's own compliance standard, that its AML/KYC controls, its source-of-funds documentation and its safeguarding arrangements meet the bank's risk appetite. The bank's decision is driven by its own regulatory environment — typically the FCA, ESMA or a US prudential supervisor — not by the crypto firm's licensing jurisdiction. A well-documented safeguarding and compliance structure, reviewed before the banking application, significantly reduces the risk of termination.

How can a VASP onboard with an EMI?

A VASP seeking EMI onboarding should prepare a compliance package that addresses the EMI's own enhanced-due-diligence requirements: corporate structure, beneficial ownership, AML/KYC policy, transaction-monitoring procedures, Travel Rule compliance status, and the safeguarding structure the VASP applies to its own client funds. The EMI will also assess transaction volume and currency mix. Engaging counsel to review the package before submission shortens the onboarding timeline and reduces the risk of a mid-process information request that stalls the relationship.

What does client-money safeguarding require?

Client-money safeguarding requires, at minimum, segregation of client funds from the firm's own money in a designated account held with a qualifying credit institution; a legal designation of the account as a trust or client-money account enforceable under the applicable insolvency law; daily reconciliation of the safeguarding balance against the firm's records of client balances; and a written policy governing discrepancies and regulatory notification. The precise requirements vary by regime — FCA, MiCA, MAS — but the core structural elements are consistent across the leading payment frameworks.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit — so that your safeguarding structure withstands both regulatory examination and banking due diligence. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when client funds are at risk. To discuss your situation, contact info@oboluslaw.com or reach us via t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst — specialising in payment-regulation and safeguarding frameworks for digital-asset businesses across EU and multi-jurisdictional structures.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours