Operating without a credible banking relationship is the fastest way to strand a digital-asset business. Regulators issue licences; banks decide whether you can move money. For a virtual asset service provider (VASP, an entity offering crypto exchange, custody or transfer services), the gap between holding a licence and holding a live fiat account is where most projects quietly fail. Corporate bank account opening under heightened scrutiny is not a compliance formality – it is a commercial survival question that requires legal preparation, not luck.
As regimes converge on the MiCA model and VASP supervision tightens across the major hubs, banks are applying more rigorous onboarding filters to crypto-related entities than to almost any other sector. A business that walks into that process without a structured presentation of its licensing, AML controls and transaction-flow logic will be declined – often silently, and often permanently in that institution. We map the banking strategy before the application goes in, not after the rejection arrives.
This page walks through the regulated basis for heightened scrutiny, the practical process for positioning a crypto company for approval, the cross-border variables that change the analysis, and a decision matrix for different operator profiles.
What "heightened scrutiny" means for a crypto company's banking application
Heightened scrutiny is the elevated due-diligence standard that financial institutions apply when a prospective client is classified as high-risk – and virtually every VASP, EMI applicant and digital-asset fund lands in that category by default. The standard is not arbitrary. It flows from FATF Recommendation 15 and its Guidance for a Risk-Based Approach to Virtual Assets, which requires financial institutions to treat VASPs as a distinct, elevated-risk customer class and to conduct enhanced due diligence accordingly.
In practice, this means a crypto company faces a substantially longer questionnaire than a conventional corporate client, requests for granular transaction-flow analysis, independent AML-policy review, source-of-funds documentation at the UBO level, and – increasingly – evidence of how the business handles the Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer). Many institutions also require a demonstrated regulatory footprint: a licence, a registration, or at minimum a credible pending application in a jurisdiction the bank recognises.
The cross-border dimension compounds the difficulty. A VASP incorporated in one jurisdiction, licensed in a second and serving users in a third will face a bank that must assess compliance across all three environments simultaneously. In our practice, we regularly advise operators who have a perfectly adequate licence but who present that structure in a way that reads as opaque rather than transparent – and the result is the same as having no licence at all.
CTA #1: The analysis above describes the standard path. Your facts – the entity, the user base, the banking relationship you need – change the analysis materially. For a scoped assessment of your banking position before you approach an institution, contact OBOLUS at info@oboluslaw.com.
What is the regulatory basis for a bank refusing a crypto company?
Banks refuse crypto company accounts under a combination of their own risk appetite, domestic AML regulation and the FATF-derived expectations embedded in their prudential supervision. No single rule mandates refusal – banks retain discretion. But that discretion is exercised against a backdrop in which a bank that onboards a non-compliant VASP faces regulatory censure, potential fines and reputational exposure. The incentive structure systematically favours rejection over approval where the applicant's compliance posture is unclear.
Under the MiCA regime applicable across the EU and EEA, credit institutions and payment service providers are required to assess the compliance status of VASPs they serve. A VASP that lacks a valid CASP authorisation (crypto-asset service provider authorisation, the licence category MiCA establishes) or that cannot demonstrate it is operating within the applicable regulatory perimeter will find EU banks under explicit supervisory pressure to limit or decline the relationship. The Bank of Lithuania, the Malta Financial Services Authority (MFSA), and the German BaFin each implement these expectations through their own supervisory guidance, meaning the specific standard varies by the bank's home regulator.
Outside the EU, the picture is equally jurisdiction-specific. In the UAE, a bank operating under the UAE Central Bank's framework will assess a VASP client against VARA's regulatory expectations for Dubai-based entities, or the FSRA's framework for ADGM entities. In Singapore, a bank supervised by MAS will scrutinise whether the VASP holds a valid licence under the Payment Services Act. In the UK, the FCA's financial-promotion rules and the Money Laundering Regulations (MLR) registration requirements function as practical reference points for bank underwriting decisions. A business that can point to active supervision under a recognised regime is materially better positioned than one presenting only an offshore registration that the bank cannot independently verify.
How does a crypto company position itself for bank approval?
Successful corporate bank account opening under heightened scrutiny begins with a structured pre-application phase, not the submission itself. The submission is the last step. The preparation – which typically runs across several weeks – determines whether the institution's compliance team recommends approval or routes the file to its high-risk rejection queue.
The preparation phase covers four elements. First, a regulatory map: a clear, documented account of every jurisdiction in which the business is licensed, registered or operating, the regulator supervising each activity, and the current status of each regulatory relationship. Second, an AML/CFT package: the business's policies, its transaction monitoring approach, its Travel Rule solution (named and operational, not aspirational), and its UBO disclosure to the level the bank will require. Third, a transaction-flow narrative: a plain-language description of where fiat enters the business, how it is handled, where crypto conversion occurs and how client money is segregated. Fourth, a financial-crime risk assessment specific to the products and customer base, demonstrating that the business has identified its own high-risk vectors and has controls in place.
We have seen applications where the business had strong AML policies but no Travel Rule solution documented. We have seen others where the transaction-flow narrative described a structure the bank's compliance team could not follow – triggering a request for clarification that, in practice, is rarely answered satisfactorily on the second attempt. The preparation phase is where these gaps are found and closed before the bank sees them.
Once the package is ready, the choice of institution matters as much as the quality of the application. Not all banks that accept crypto clients accept them on equal terms. Some will require the account to be ring-fenced from fiat-to-crypto conversion flows. Some will cap transaction volumes. Some will require periodic recertification. Matching the business's profile to an institution's stated appetite – and understanding the nuances of each bank's internal risk-categorisation approach – is part of the service, not a preliminary.
Can an EMI onboard where a bank declines?
An electronic money institution (EMI, an entity licensed to issue electronic money and provide payment services) is increasingly the practical route to fiat rails for crypto businesses that cannot access a direct bank relationship. EMIs operating under MiCA-adjacent payment frameworks in EU jurisdictions – Lithuania and Malta in particular – have developed onboarding protocols specifically for VASP clients, and their risk appetite is generally broader than that of a tier-one bank.
The trade-off is real. EMI accounts typically carry lower transaction limits than a correspondent-banking relationship, may restrict certain currency pairs, and do not provide the balance-sheet depth or settlement finality that a clearing bank delivers. For an exchange processing significant institutional volume, an EMI account is a bridge, not a destination. For an early-stage VASP or a business entering a new geographic market, it is often the only viable path while a direct banking relationship is cultivated.
The regulatory basis for the EMI's own onboarding decision mirrors the bank's. An EMI licensed by the Bank of Lithuania must conduct its own enhanced due diligence on a VASP client, assess the VASP's compliance posture, and document the risk assessment in its own files. The VASP's burden of proof is structurally the same. What differs is the EMI's institutional risk tolerance and its familiarity with crypto-specific compliance presentations.
Operators we advise routinely combine an EMI account for initial market entry with a parallel banking strategy targeting a tier-two bank in a crypto-friendly jurisdiction. The two-track approach keeps the business operational while the primary banking relationship develops.
How do cross-border structures affect the banking application?
The cross-border reality of most digital-asset businesses is the single biggest complicating factor in bank onboarding. A structure that places the operating entity in one jurisdiction, the custody function in a second and the treasury in a third is commercially rational – but it creates a compliance narrative that a bank's onboarding team must work to understand, and that most will not invest the time to investigate without guidance.
FATF's risk-based approach explicitly identifies multi-jurisdictional structures as a red flag that warrants enhanced scrutiny. The bank is not wrong to apply that scrutiny. The answer is not to simplify the structure – which may be driven by legitimate regulatory, tax or operational logic – but to document it clearly enough that the scrutiny is satisfied rather than deepened.
The specific variables that shift the analysis most significantly are: where the entity is licensed (and whether that jurisdiction is on the bank's approved-regulator list), where the UBOs are resident (and whether those jurisdictions present source-of-funds complexity), where the customers are located (and whether they include sanctioned jurisdictions or high-risk nationals), and where the fiat flows transit (which correspondent banks are involved, and whether any of them flag for the bank's internal compliance). Each of these elements is a potential rejection trigger. Each is also manageable with the right preparation.
In a recent matter, a payments company structured across three jurisdictions approached two banks sequentially and was declined by both. We reviewed the application package and identified that the transaction-flow narrative created an ambiguity about which entity held client money at each stage of a transfer cycle. That ambiguity was not a structural problem – the structure itself was sound. It was a documentation problem. After we restructured the presentation and produced a revised client-money map, the business secured an account with a third institution within a matter of weeks.
What are the most common mistakes that lead to rejection?
Rejection at the bank-onboarding stage is rarely random. In our practice, the same preparation failures appear repeatedly, across jurisdictions and operator profiles.
The first is presenting a licence without explaining its scope. A VARA licence in Dubai, a CASP authorisation under MiCA, and an MLR registration with the FCA each authorise a different perimeter of activity. A bank that cannot immediately match the licence to the business's described activities will treat the gap as a compliance concern – fairly or not.
The second is an AML policy that describes intent rather than process. Banks want to see how transaction monitoring works in practice: the thresholds, the escalation chain, the record-keeping approach, and – critically – the outcome data. A policy document that lists good intentions and names software without describing how it is configured and reviewed is not a compliance presentation; it is a template.
The third is Travel Rule non-compliance, or a vague assertion that a Travel Rule solution is "under implementation." From a bank compliance officer's perspective, a VASP that cannot demonstrate an operational Travel Rule solution is a business that is not yet compliant with a core FATF expectation. In a heightened-scrutiny environment, that is a rejection reason, not a flag for follow-up.
The fourth is UBO documentation that is incomplete or inconsistent across jurisdictions. If a UBO holds interests through multiple entities in different jurisdictions, each layer must be documented to the same standard. Gaps at any level will pause the application – and a paused application in this environment rarely restarts.
A common assumption among operators is that a single offshore licence is sufficient to demonstrate regulatory credibility to any bank globally. It is not. A bank's approved-regulator list is specific to its own compliance programme and its prudential supervisor's expectations. An operator licensed in a jurisdiction the bank does not recognise, or cannot verify, is in the same position as an unlicensed operator from the bank's perspective.
CTA #2: If a prior application stalled or an account was closed, a second read of the package can surface the structural reason and the route back. Write to OBOLUS at info@oboluslaw.com to arrange a confidential review.
Which banking strategy fits your operator profile?
The right approach depends on the business's current regulatory status, its transaction volumes, its geographic footprint and the urgency of its fiat-rails requirement. The following profiles are illustrative.
Profile A: Early-stage VASP, single-jurisdiction licence, sub-institutional volumes. The recommended path is an EMI account in a crypto-accessible EU jurisdiction – Lithuania or Malta under MiCA – combined with a parallel application to a tier-two bank that has a documented crypto-client programme. The EMI provides operational rails within weeks. The banking relationship targets a three-to-six-month horizon. The key risk at this stage is the EMI's own transaction limits, which may constrain growth faster than anticipated.
Profile B: Growth-stage VASP, multi-jurisdiction structure, mixed retail and institutional flows. The requirement is typically a direct banking relationship, not an EMI. The preparation phase is more intensive because the compliance narrative is more complex. The most productive institutions at this stage are mid-market banks in crypto-experienced jurisdictions – including, depending on the structure, banks operating under the supervision of the Bank of Lithuania, the MFSA or, for UAE-domiciled entities, banks familiar with VARA's regulatory environment. Timeline to approval varies by institution and the completeness of the application package.
Profile C: Established operator, institutional counterparties, cross-border treasury function. The banking strategy at this level must be multi-bank: a primary clearing relationship, a secondary operational account and potentially a treasury account in a separate jurisdiction for currency management. The compliance preparation is correspondingly sophisticated. Each institution will conduct its own enhanced due diligence, and the presentations must be consistent across all of them without being identical – because each bank's questionnaire is slightly different. Allied counsel in the relevant jurisdictions typically coordinates the local regulatory verification that each bank will require.
What does client-money safeguarding require, and why does it matter to banks?
Client-money safeguarding is the regulatory obligation to hold client funds separately from the firm's own funds, in a way that protects them in an insolvency. It matters to banks because the account structure the bank is being asked to provide is central to how safeguarding works – and a bank that hosts an account into which client money flows without appropriate segregation is potentially implicated in the compliance failure.
Under MiCA's applicable provisions, CASPs holding client funds are required to segregate those funds and ensure they are not used for the firm's own account. The practical implementation – whether through a designated client-money account, a safeguarding account with a credit institution or, for EMI issuers, holding funds in sovereign-debt instruments – affects the account structure the bank is being asked to create. The bank's onboarding team will want to understand exactly what role the account plays in the safeguarding architecture before it approves.
A VASP that cannot clearly describe how client money is segregated, at which legal entity it sits, under which regulatory framework the segregation obligation arises, and how the bank account fits that structure will almost certainly not be approved for a client-money account at a regulated institution. The segregation narrative is, in our experience, one of the most underestimated elements of a banking application – and one of the most consequential.
We map the licence, banking and structural stack for operators before the first application goes in. To discuss your structure, write to info@oboluslaw.com or message us via t.me/oboluslaw.
Related at OBOLUS
- Banking, Payments and EMI Onboarding – the full practice overview for digital-asset businesses seeking fiat rails
- Fiat On/Off-Ramp Banking in Lithuania – EMI and banking options under the Bank of Lithuania's supervision
- Digital Asset Custody Authorisation in Malta – custody licensing under the MFSA and the MiCA CASP regime
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily when a client's compliance posture no longer meets the institution's enhanced due-diligence standard. Common triggers include a failure to produce updated AML documentation, a change in transaction patterns that the bank cannot reconcile with the stated business model, a Travel Rule non-compliance finding, or a broader de-risking decision driven by the bank's prudential supervisor. In each case, the legal and regulatory basis is the bank's own risk-management obligations under applicable AML frameworks – not a specific prohibition on serving VASPs.
How can a VASP onboard with an EMI?
A VASP onboards with an EMI by submitting an enhanced due-diligence package that demonstrates its own regulatory status, AML controls, Travel Rule compliance and UBO structure to a standard the EMI can document in its own risk files. The EMI is itself a regulated entity – typically under a payment-services or e-money licence – and is required by its home regulator to treat VASPs as high-risk clients. The quality and completeness of the compliance presentation determines outcome. A well-prepared package, matched to an EMI that actively serves the VASP sector, materially improves the probability of approval.
What does client-money safeguarding require?
Client-money safeguarding requires a regulated firm to hold client funds separately from its own funds in a way that protects them in an insolvency. Under MiCA and equivalent regimes, this means a dedicated segregated account, clear documentation of which entity holds the funds, under which regulatory framework the obligation arises, and how the account structure implements that obligation. A bank asked to host a client-money account will require this information before approval. The specific mechanics – whether a designated client-money account, a safeguarding account or another approved method – vary by jurisdiction and licence category.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – so the banking strategy is built on the right structural foundation. Our disputes team also coordinates freezing relief and on-chain tracing across leading common-law forums when matters turn adversarial. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP regulatory positioning, bank onboarding preparation and cross-border compliance architecture for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.