For a digital-asset business, the absence of a functioning corporate bank account is not merely an operational inconvenience. It is an existential constraint. Exchanges cannot settle trades. Custodians cannot pay counterparties. Token issuers cannot receive subscription proceeds. Operating without stable fiat rails (the bank and payment-system connections that convert digital assets into usable currency) exposes a business to frozen settlements, regulatory attention and client attrition — often simultaneously. The cross-border dimension compounds every risk: the entity may be licensed in one jurisdiction, its users seated in another and its preferred banking partner domiciled in a third. That three-way mismatch is where most corporate bank account opening attempts fail.
Corporate bank account opening from a cross-border perspective requires more than a clean compliance file. It requires a structured account of who the entity is under each applicable regulatory regime, what EMI onboarding (the process of engaging an e-money institution as a payment counterpart) adds to or substitutes for a traditional bank relationship, and how the payment licence stack interacts with the underlying VASP or CASP authorisation. We regularly advise clients through this process across multiple jurisdictions and banking partners.
This page sets out the regulated basis for corporate banking access, the mechanics of the application process, the most common failure points and the decision matrix an operator should work through before committing capital and management time to an account-opening program.
Why Banks Reject Crypto Clients — and What Has Changed
Banks decline digital-asset businesses primarily on risk-appetite grounds, not always on legal prohibition. A bank's risk committee typically weighs the reputational exposure of the sector, the cost of enhanced due diligence and the uncertainty of the applicable regulatory regime against the revenue the account will generate. Until recently, that calculus almost always resolved against onboarding. The environment has shifted. MiCA authorisation by ESMA-supervised competent authorities now provides a recognized European-level credential that many correspondent banks treat as a de-risking signal. Similarly, VARA licensing in Dubai and the FCA's registration regime in the United Kingdom have introduced compliance frameworks that a growing number of relationship banks accept as a substitute for bespoke due diligence.
The operative shift is institutional credibility. A CASP authorisation under MiCA signals that an operator has passed AML/KYC scrutiny, holds minimum capital, maintains an auditable compliance program and is subject to ongoing regulatory supervision. A bank's compliance team can point to that credential in its own onboarding file. Absent the credential, the bank must do the supervisory work itself — and it generally will not.
That said, authorization alone does not guarantee an account. Banks and EMIs (e-money institutions licensed under national transpositions of the EU's Electronic Money Directive, or equivalent regimes) retain full discretion over client acceptance. The gap between "licensable" and "bankable" remains real.
For a scoped assessment of your entity's bankability profile, contact OBOLUS at info@oboluslaw.com. The structure of your licence, the jurisdiction of incorporation and the composition of your user base all affect the analysis before the first bank conversation begins. Map your options
What Is the Regulated Basis for a Digital-Asset Business to Access Banking?
A digital-asset business gains durable banking access by establishing itself as a regulated counterpart that a bank can defend to its own compliance function. The specific regulatory basis varies by jurisdiction, but the principle is consistent: recognized authorization reduces the bank's risk cost.
Under MiCA, a CASP authorization issued by a national competent authority and notified to ESMA provides EU-wide legal standing. That authorization carries obligations — capital adequacy, client-asset segregation, complaint handling, ongoing supervisory reporting — that directly parallel the expectations a bank's Know Your Business process would otherwise impose. In practice, a passported MiCA CASP from a credible member-state NCA (such as the Bank of Lithuania under the MiCA transition, or the MFSA in Malta as its VFA framework converges toward MiCA CASP) commands notably better traction in European banking discussions than an entity with only a legacy offshore registration.
Outside the EU, the VARA regime in Dubai and the FSRA regime in ADGM serve the same function for Middle Eastern banking relationships. The MAS Payment Services Act regime in Singapore and the SFC's VASP licensing regime in Hong Kong anchor banking conversations in Asia-Pacific. Each regime signals that the operator has been scrutinized. Each carries its own capital and compliance cost. The choice of primary licensing jurisdiction should be made with a specific view to where the banking will live.
In our cross-border practice, we have seen operators license in a jurisdiction optimized for speed and then discover that their target banking partners — typically in Switzerland, Germany or the Netherlands for European operators — apply their own internal list of acceptable licensing regimes. A licence issued in a jurisdiction that does not appear on the bank's approved-counterpart list fails the first internal compliance screen, regardless of its legal validity.
EMI Onboarding as a Practical Alternative to Traditional Banking
An EMI (e-money institution), licensed under an applicable national regime to issue electronic money and provide payment services, can provide a digital-asset business with most of the functional capabilities of a traditional bank account: IBAN issuance, SEPA and SWIFT payment routing, multi-currency holding and, in some cases, FX conversion. For operators that cannot secure a relationship with a tier-one bank, EMI onboarding has become the standard first-step solution for stabilising fiat rails.
The EMI onboarding process is structurally similar to bank onboarding but typically more accessible for digital-asset clients. EMIs are themselves regulated — under MiCA-adjacent payment legislation in the EU, under the FCA in the United Kingdom and under equivalent national payment-services regimes elsewhere — and their compliance functions are purpose-built for technology-sector clients. The tradeoff is capacity: EMIs generally carry lower transaction limits than correspondent banks, may not offer direct access to central-bank settlement systems and introduce their own counterpart risk into the payments stack.
A further practical consideration is correspondent banking. An EMI's own SWIFT access depends on its relationship with a sponsoring correspondent bank. If that correspondent applies sector exclusions, the EMI's ability to process payments for crypto-business clients can be interrupted without notice. Operators we advise are encouraged to maintain relationships with at least two EMIs in different jurisdictions for this reason, treating each as a structural redundancy rather than a preferred provider.
The interaction between EMI onboarding and the underlying VASP or CASP licence is also legally material. An EMI that onboards a client operating an unlicensed virtual-asset exchange may itself face regulatory scrutiny for enabling unregistered financial activity. That exposure makes the EMI's own due diligence intensive and, in some cases, leads to pre-emptive offboarding when a client's licensing status becomes unclear.
How Does the Corporate Bank Account Opening Process Actually Work?
Corporate bank account opening for a digital-asset business follows a defined sequence, and most failures occur at identifiable points within that sequence. Understanding the structure in advance allows an operator to prepare documentation that addresses each checkpoint proactively rather than reactively.
The process typically begins with a relationship introduction — either through a legal adviser, an existing banking contact or a direct application to the bank's innovation or fintech team. Cold applications to major banks for digital-asset clients almost never succeed; the introduction signal matters as much as the compliance file.
Following the introduction, the bank or EMI issues a Know Your Business questionnaire. For digital-asset operators, this questionnaire is substantially more detailed than for conventional corporate clients. It will typically address: the legal basis of the entity's digital-asset activities (the licence or registration, and the jurisdiction); the nature of the assets handled (the distinction between payment tokens, stablecoins and securities-like tokens); the client profile of the business (institutional clients only vs. retail-facing, geographies served); the AML and Travel Rule compliance program (the Travel Rule being the obligation under FATF Recommendation 15 to pass originator and beneficiary data with virtual-asset transfers); and the banking history of the entity and its controllers.
The bank's compliance team then conducts an enhanced due diligence review. This review may include a request for the operator's full regulatory correspondence, its AML risk assessment, its source-of-funds documentation for initial capital and its technology architecture as it relates to transaction monitoring. For operators with a prior banking relationship that was terminated, the reasons for that termination will be a central focus.
Approval timelines vary materially by institution and jurisdiction and cannot be stated as a fixed number. In our experience, well-prepared applications to receptive institutions resolve within a matter of weeks; applications that require repeated supplemental documentation rounds extend materially beyond that. The preparedness of the application package is the single most controllable variable.
Where Does Cross-Border Complexity Create the Most Risk?
For a business operating across multiple jurisdictions, the cross-border dimension of corporate banking introduces legal and practical risks that a single-jurisdiction analysis will miss. The most consequential arise at three intersections.
First, the licence-banking geography mismatch. A business licensed in Lithuania under the MiCA transition regime but seeking to bank in Switzerland will encounter a Swiss bank applying its own assessment of the Lithuanian supervisory framework. The bank may request additional documentation about the NCA's supervision intensity, capital adequacy standards and AML inspection history. A business licensed under VARA in Dubai that seeks a European IBAN for Euro settlement will face the same evaluation. Neither the Lithuanian NCA nor VARA controls the Swiss bank's credit decision.
Second, sanctions and restricted-party screening. Banks apply their own sanctions overlay — OFAC, EU consolidated list, UK financial sanctions — to every transaction processed through an account. A digital-asset business whose client base includes users from sanctioned territories, even inadvertently, creates a compliance exposure that a bank's transaction monitoring system will flag. The bank does not need a regulatory direction to close the account; internal policy suffices. Operators we advise in high-risk geographies maintain detailed geographic restriction logs and transaction-monitoring reports specifically to pre-empt this conversation.
Third, the corporate structure itself. Many digital-asset businesses operate through layered structures — an operating company in one jurisdiction, a holding company in another, a token-issuing entity in a third. Banks assess each entity individually. A clean holding company will not rescue an operating subsidiary that the bank's KYB process flags as problematic. We map the full entity stack before advising on which entity should hold the primary banking relationship and which should be presented as the account holder in each jurisdiction.
What Are the Most Common Mistakes That Delay or Prevent Account Opening?
A common assumption is that the quality of the underlying business is the primary determinant of banking success. In practice, the presentation of that business — the sequence of disclosures, the structure of the compliance file and the choice of entry channel — matters at least as much.
The most frequent error we observe is premature approach. An operator contacts a bank before its regulatory authorization is complete, before its AML program is documented and before its corporate structure is finalized. The bank notes the application, flags the entity as insufficiently prepared and — in some cases — creates an internal record that impedes a later application. Approaching a bank before the compliance architecture is complete is rarely recoverable within the same banking relationship.
A second common error is jurisdiction shopping for the licence without reference to the banking target. Operators select a licensing jurisdiction based on speed or cost and only later discover that their preferred banking partners do not recognize that regime. The licence and the banking relationship must be selected in tandem.
A third error is under-disclosure of the business model. A bank that later discovers that a client's activities include services not described in the initial onboarding file will treat the discrepancy as a compliance failure, not an administrative oversight. That typically results in account closure and reputational damage in the banking community, which is small and communicates efficiently.
In a recent banking advisory matter, a payments company incorporated in a recognized EU jurisdiction approached three major banks sequentially over the course of several months, receiving rejections each time. When we reviewed the onboarding materials, the AML risk assessment referenced a template policy that had not been customized to the company's actual business model. The client profile section described a retail-facing exchange when the business was, in practice, institutional-only. We restructured the compliance file, introduced the client through a banking intermediary relationship and the account was opened within weeks of resubmission.
Decision Matrix: Which Banking Route Fits Which Operator Profile?
The right banking strategy depends on the operator's license, its user base, the currencies it needs and its risk tolerance for banking disruption. The following profiles illustrate the most common configurations we work through.
Profile A: Early-stage CASP applicant, EU-focused, institutional clients only. The appropriate initial route is an EMI onboarding in a MiCA-friendly EU jurisdiction (Malta and Lithuania both have active EMI sectors familiar with digital-asset clients), combined with a banking introduction process run in parallel with the CASP application. The operator accepts that the EMI relationship is a transitional structure and builds toward a relationship bank once the CASP authorisation is confirmed. The primary risk is EMI capacity constraints and correspondent-bank interruption.
Profile B: Licensed VASP in the UAE, serving GCC and Asian clients with a USD/AED settlement need. The operator's primary banking target should be within the GCC, where VARA and ADGM/FSRA credentials are well understood. European EMI onboarding for Euro access is a secondary priority. A SWIFT-connected account in a recognized UAE free-zone bank, combined with a payment-services relationship for USD transfers, covers the operational requirement. The primary risk is the KYB depth that UAE correspondent banks apply to retail-facing digital-asset businesses.
Profile C: Offshore-structured fund or token issuer seeking multi-currency banking for investor subscriptions. The BVI FSC and Cayman CIMA regimes provide recognized investment-fund frameworks but do not of themselves resolve the banking question. This profile typically requires a banking relationship in a jurisdiction with a robust private-banking sector — Switzerland or Luxembourg — combined with demonstrated institutional investor counterparts and a clean source-of-funds chain. Timelines here are longer and the due diligence intensity is higher. The primary risk is that the fund's token exposure is categorized as an unregulated securities position by the bank's compliance team.
If a prior application stalled or a banking relationship was closed, a structural review can identify the specific failure point and map the route back. Contact OBOLUS at info@oboluslaw.com or via t.me/oboluslaw. Map your options
Self-Assessment: Is Your Business Ready for a Banking Approach?
Before initiating any formal banking or EMI onboarding process, the following questions should be answered in full. An unresolved question at any point in this list predicts a delay or rejection downstream.
- Is the entity's regulatory authorization complete, current and issued by a jurisdiction the target bank recognizes?
- Has the AML/CFT program been documented, tested and updated to reflect the actual current business model — not a projected or template model?
- Does the business maintain a written Travel Rule compliance procedure, naming the specific solution used for originator/beneficiary data transmission?
- Is the corporate structure finalized, with beneficial ownership documents current and consistent across all group entities?
- Has the source of initial capital been documented to a standard that would satisfy a bank's enhanced due diligence review?
- Are there any prior banking terminations, regulatory adverse findings or sanctions-screening flags that must be disclosed proactively?
- Is there an identified introduction channel to the target bank — an existing relationship, a legal adviser or a recognized intermediary?
Operators who can answer each of these questions affirmatively, with documented evidence, are in a position to proceed. Those who cannot should resolve the gaps before making any approach. A premature approach with an incomplete file is generally worse than a delayed approach with a complete one.
Related at OBOLUS
- Banking, Payments and EMI Onboarding – full practice overview for digital-asset businesses seeking fiat rails
- PSP and Acquiring Agreements in Malta – how Malta's payment-services regime interacts with MFSA licensing
- Staking Service Legal Framework for Established Operators – the regulatory and structural considerations for operators adding staking to the product suite
FAQ
Why do banks close crypto company accounts?
Banks close digital-asset company accounts primarily on risk-appetite and compliance grounds. The most common triggers are: a change in the bank's internal sector policy; a transaction-monitoring alert that the bank's compliance team cannot resolve within its own procedures; undisclosed changes in the client's business model; and geographic expansion into sanctioned or high-risk territories. A license from a recognized regulator reduces — but does not eliminate — the risk of closure, because the bank's own credit and compliance decisions remain fully discretionary. Maintaining current regulatory credentials, transparent reporting and a proactive relationship with the account manager is the most effective mitigation.
How can a VASP onboard with an EMI?
A VASP (virtual asset service provider) onboards with an EMI by demonstrating that it meets the EMI's own risk-acceptance criteria, which typically include: confirmed regulatory registration or authorization in a recognized jurisdiction; a documented AML/CFT program; a clear description of the business model and client profile; and source-of-funds documentation for initial and operating capital. The EMI conducts its own enhanced due diligence and may require ongoing transaction reporting. Preparation of the onboarding file to the same standard as a bank KYB submission — not a lighter version — significantly improves the outcome.
What does client-money safeguarding require?
Client-money safeguarding requires that a regulated entity — whether an EMI, a payment institution or a CASP under applicable obligations — hold client funds separately from its own funds, in a designated account with an authorized credit institution or in qualifying liquid assets. The specific requirements vary by jurisdiction and licence category. Under MiCA and equivalent payment-services regimes, the safeguarding obligation applies from the moment client funds are received. Failure to maintain proper segregation is both a regulatory breach and, in an insolvency scenario, a significant risk to client recovery. The precise mechanics should be confirmed against the applicable regime at authorization.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit — so that the banking conversation starts from a defensible position. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst — specialising in the intersection of VASP/CASP authorization and banking access across the major licensing hubs.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.