EST · MMXXVI
Home/Services/Banking Payments Emi/Corporate bank account opening for Regulated Entities
Banking, Payments & EMI Onboarding

Corporate bank account opening for Regulated Entities

Corporate bank account opening for Regulated Entities. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOL

Regulated digital-asset businesses face a narrowing window. Banks and electronic money institutions (EMIs – firms authorised to issue electronic money and provide payment services) are tightening their onboarding criteria for crypto-related corporates. A virtual asset service provider (VASP) that holds a licence in one jurisdiction but cannot open a functional account in another will find its fiat rails cut before it can serve a single client. The consequence is not inconvenience – it is an inoperable business.

Corporate bank account opening for regulated entities is a structured legal and compliance exercise, not an administrative formality. The outcome turns on how the entity is characterised, how its regulatory status is documented, and how its transaction profile is explained to a risk-averse counterparty. In our practice, a poorly presented application from a well-licensed operator fails as reliably as an application from an unlicensed one.

This page sets out the regulated basis for the process, the common structural mistakes, the cross-border dimension, and the decision logic a general counsel or CFO should apply before committing capital to any banking relationship.

Why banking fails even for properly licensed crypto businesses

The most common misconception in our practice is that a VASP licence resolves the banking problem. It does not. A licence confirms regulatory permission to operate. It does not oblige a bank to accept the account. Banks make a separate, commercial risk decision – and for digital-asset businesses that decision is frequently negative, regardless of the applicant's compliance posture.

The structural reason is that most retail and commercial banks operate under correspondent banking agreements that restrict their exposure to high-risk business categories (a classification applied broadly to VASPs, crypto exchanges, custodians and token issuers by de-risking policies adopted across the major correspondent networks). A bank that accepts a crypto-related corporate account assumes Travel Rule (the FATF obligation requiring originator and beneficiary information to accompany virtual-asset transfers) monitoring obligations and potential reputational exposure that its compliance function is rarely resourced to absorb.

The implication for a regulated entity is direct: the banking application must do work that a standard corporate onboarding package does not. It must characterise the business model in terms a bank compliance officer can approve, map the regulatory status to the bank's own risk appetite, and pre-empt the questions that cause an application to stall.

Operators we advise routinely underestimate the volume of supplementary documentation a bank's financial crime team will request – and the time that elapses between submission and a decision. That gap is measured in weeks to months at most institutions, and a single missing document resets the clock.

What is the regulated basis for account opening?

Account opening for a regulated VASP is governed by the AML/CFT framework of the bank's jurisdiction, not the applicant's home regime. A VASP licensed under the Dubai VARA regime applying to a European bank must satisfy that bank's obligations under the applicable Anti-Money Laundering directives and the bank's own FATF-aligned risk appetite – regardless of how sophisticated the VARA licence is.

This creates a layered problem. The applicant's regulator – whether VARA, the MFSA in Malta, the AFSA within Kazakhstan's AIFC, or the FCA in the United Kingdom – has authorised the business to operate. The counterparty bank, however, applies its own risk matrix, which is typically calibrated to the most restrictive interpretation of its home regulator's guidance. A UK-based bank, for example, applies FCA financial-crime expectations to every corporate client it onboards, including foreign VASPs seeking an account for their European operations.

The same asymmetry appears with EMIs. An EMI operating under a MiCA-aligned authorisation granted by a national competent authority in the EU can provide payment accounts and issue electronic money. But the EMI's own AML obligations under the applicable EU anti-money-laundering regime require it to conduct enhanced due diligence on VASPs as business customers. In practice, many EMIs cap their VASP onboarding at a volume they can monitor, or decline it altogether.

Understanding which regulatory framing applies to the counterparty – not just to the applicant – is the first analytical step. We map this before a client submits anything.

For a scoped assessment of your banking position, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking counterparty – change the analysis materially.

Which institutions actually onboard VASPs and custodians?

The realistic universe of banking counterparties for a regulated digital-asset business is smaller than most founders expect, and it is segmented by licence type, jurisdiction of incorporation, and transaction profile.

In our cross-border practice, the accounts that work tend to fall into three categories. First, specialist digital-asset banks – institutions in Switzerland under FINMA supervision, for example, or in jurisdictions that have built a regulatory environment designed to attract the sector. These institutions understand the asset class and apply a calibrated risk model. Second, certain EMIs licensed under MiCA or under the Payment Services Act in Singapore, whose business model includes VASP clients as a defined segment. Third, regional and challenger banks in jurisdictions with a developed VASP regime – the DIFC financial free zone in Dubai and the ADGM in Abu Dhabi, for example, sit within ecosystems where banking for licensed entities is structurally more available.

The critical variable is not which institution is theoretically willing. It is which institution has the compliance infrastructure to manage the ongoing monitoring obligations for a VASP client profile. An institution that onboards a VASP but cannot sustain the monitoring will close the account within months. We have seen that outcome repeatedly, and it is as damaging to a business as a failed initial application.

A decision on where to apply must therefore weigh the probability of initial acceptance against the durability of the relationship. Short-term access through a counterparty with no VASP compliance capability is not a banking solution.

What does the application process require in practice?

A bank account application for a regulated digital-asset entity typically requires a documentation package substantially more detailed than a standard corporate onboarding. The core components are: the entity's regulatory authorisation and any conditions attached to it; the group structure and UBO (ultimate beneficial owner) chain to natural persons; the AML/CFT policy and procedures, evidencing Travel Rule compliance; the business model description, segmented by revenue stream and client type; and projected transaction volumes and corridors, including the fiat and crypto pairs the account will be used to settle.

Beyond the document package, the application process almost always involves a compliance interview. A bank's financial-crime team will want to speak with the CMLRO (Chief Money Laundering Reporting Officer) or equivalent. The quality of that conversation – the specificity of the answers, the demonstrated understanding of the bank's concerns – materially affects the outcome.

Timeline varies by institution and jurisdiction. In our experience, applications to specialist digital-asset banks or crypto-friendly EMIs can move in weeks when the package is complete. Applications to tier-one retail banks in conservative jurisdictions rarely conclude in under several months, and are frequently declined regardless of preparation quality. The pragmatic approach is to run parallel applications to institutions in different risk tiers rather than sequencing them.

Common mistakes at the application stage: submitting an incomplete AML policy that does not address Travel Rule obligations; providing a group structure chart that does not resolve to natural persons; and failing to address the source-of-funds question for the crypto assets the account will interact with. Each of these predictably triggers a request for further information – or a quiet decline.

How does the cross-border structure affect the banking strategy?

A business licensed in one jurisdiction but serving clients in several faces compounding banking complexity. The entity's home regulator may require client-money accounts in certain formats; the banking counterparty's jurisdiction may impose different segregation standards; and the client's jurisdiction may restrict the use of foreign-based payment accounts entirely.

The cross-border dimension becomes acute when a VASP holds, for example, a MiCA CASP authorisation passported across EU member states, but its primary banking counterparty is an EMI licensed in a single member state with restricted cross-border IBAN issuance. The CASP's regulatory passport does not extend to the banking relationship. The operator must separately address the payment infrastructure in each market it serves, or work through an EMI that has its own EU-wide presence.

A parallel issue arises with custody. A custodian regulated under the FSRA in Abu Dhabi's ADGM, serving institutional clients whose assets are denominated in US dollars, must resolve its USD correspondent banking separately. ADGM banks do not automatically provide USD nostro access, and the correspondent chain may require a separate relationship with a bank in a jurisdiction where the custody model is classified differently. We have structured solutions across this configuration for clients in the Gulf region and East Asia, using allied counsel in the relevant jurisdictions to address local banking law.

The key principle is that the banking strategy must follow the legal structure – not precede it. An entity incorporated for operational speed, without regard to the banking implications of that jurisdiction choice, will encounter banking constraints that are difficult to resolve without restructuring.

Which structure should your business choose?

The right approach depends on the operator's profile, the licence already held or being sought, and the jurisdictions in which clients are located. The following decision logic applies across the typical configurations we advise on.

A regulated exchange or trading platform with a VARA authorisation in Dubai and European users will generally need at minimum one EU EMI relationship for euro settlements and one account at a specialist institution for operational crypto-fiat conversion. The VARA licence is the anchor; the EU EMI is the fiat rail. The two are complementary but independently negotiated. Timeline to establish both rails, assuming a complete application, is typically measured in months rather than weeks.

A custodian holding a MiCA CASP authorisation and seeking USD and EUR client-money accounts will find its options concentrated in the EMI segment. Tier-one banks in the EU remain cautious on custody clients. The relevant risk factor is the safeguarding obligation: under MiCA, client assets must be safeguarded in a defined manner, and the banking counterparty must be able to accommodate that structure. Not all EMIs can. Selecting an EMI that cannot support compliant client-money segregation exposes the custodian to regulatory breach, not merely operational friction.

An early-stage exchange with a BVI FSC or Cayman CIMA registration and no EU licence has the fewest banking options. Offshore jurisdictions with VASP registration frameworks are not treated as equivalent to MiCA or VARA licensees by most banking counterparties. The structural recommendation in this scenario is to pursue an EU or UAE licence in parallel with banking outreach, treating the two workstreams as simultaneous rather than sequential.

If a prior application stalled or a banking relationship was closed, contact OBOLUS at info@oboluslaw.com. A second read of the structure and the application can surface the underlying reason and the route forward.

What does client-money safeguarding require from the banking relationship?

Client-money safeguarding is a regulatory obligation, not a commercial preference – and it constrains the choice of banking counterparty more than most operators anticipate. Under MiCA and the applicable EU payment-services regime, a CASP or EMI holding client funds must maintain those funds in a designated safeguarding account, segregated from own funds, at an institution that meets the applicable credit-quality standard.

The practical constraint is that not every bank or EMI willing to onboard a VASP is also willing to act as the safeguarding institution for that VASP's client funds. The account structure, the daily reconciliation expectations, and the reporting obligations associated with a client-money account are operationally burdensome for a bank whose core business is not financial services infrastructure. Specialist institutions and certain EU payment institutions are equipped for this role; most retail banks are not.

In the Singapore context, the Monetary Authority of Singapore's Payment Services Act regime imposes safeguarding obligations on major payment institutions that handle customer funds. The banking counterparty for those funds must itself be a MAS-regulated institution or one meeting the MAS-prescribed equivalent standard. This creates a closed loop: the operator must use a banking counterparty already operating in the same regulatory perimeter.

A common and serious mistake is treating the safeguarding account as a standard corporate account opened with the same bank as the operational account. Regulators in multiple jurisdictions have cited this conflation as a compliance failure. The accounts must be structurally distinct, clearly designated, and maintained in accordance with the applicable regime.

A common assumption – and what the evidence shows

A common assumption among operators we engage is that a single offshore licence – whether a BVI VASP registration or a Cayman VASP Act registration – is sufficient to establish banking relationships globally and serve clients across jurisdictions. The evidence in our practice is consistently to the contrary.

Banking counterparties in the EU, Singapore, Hong Kong and the United Kingdom apply their own regulatory standards to the applicant, not the applicant's home regime. An entity with a Cayman registration is assessed by a UK bank under the FCA's financial-crime and risk standards, not the CIMA VASP framework. The licence provides a basis for arguing legitimacy; it does not discharge the due-diligence obligation of the bank.

The cross-border reality is that serving clients in a jurisdiction typically requires either a local licence or a recognition mechanism – and in most major markets, neither offshore registration nor a licence from a third-country regime provides the recognition needed to establish durable banking. MiCA's passporting mechanism operates within the EU/EEA. VARA's authorisation covers mainland Dubai, not the DIFC financial free zone or the broader UAE banking system. Each layer requires separate analysis.

In a recent matter, a licensed operator in the Gulf region had been declined by three banking institutions in sequence, each citing AML risk without elaboration. We reviewed the application package and identified two structural issues: the UBO chain was documented to a holding company level rather than to natural persons, and the AML policy described procedures that post-dated the submission date, making the compliance posture appear prospective rather than operational. After restructuring the package and conducting a pre-submission call with the institution's compliance team, the account was approved within several weeks. The banking relationship has remained stable.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily for two reasons: the account profile deviates from what was disclosed at onboarding, or the bank's correspondent banking policy changes to restrict VASP exposure. A high volume of incoming transactions from unverified crypto exchanges, insufficient Travel Rule compliance documentation, or a sudden spike in transaction volume relative to projections will each trigger a review. In most cases the closure is preceded by a request for information that goes unanswered or is answered inadequately.

How can a VASP onboard with an EMI?

A VASP seeking an EMI account must present its regulatory authorisation, full UBO documentation, an operational AML/CFT policy addressing the Travel Rule, and a transaction-volume forecast segmented by corridor and asset type. The EMI will apply enhanced due diligence given the VASP's risk classification. Preparation of a clear, pre-emptive disclosure package – rather than waiting for the EMI's questions – materially accelerates the process and reduces the rate of supplementary information requests that stall timelines.

What does client-money safeguarding require?

Client-money safeguarding requires that funds belonging to clients be held in a separately designated account, structurally distinct from the operator's own funds, at an institution meeting the applicable credit-quality standard set by the relevant regulator. Under MiCA, the applicable EU payment-services regime, and the MAS Payment Services Act framework, the safeguarding institution must itself be regulated to the required standard. Using a standard operational account for client funds – even at a reputable bank – constitutes a compliance failure under most leading regimes.

About OBOLUS

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your banking strategy, contact info@oboluslaw.com or message us via t.me/oboluslaw.

By Victor Olsen, Regulatory and Compliance Analyst – specialising in VASP licensing, AML frameworks and cross-border banking onboarding for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours