Early-stage crypto founders routinely build the product, obtain a licence and then discover the hardest problem: no bank will hold their fiat. Correspondent banking access – the ability to place and receive funds through the network of banks that clear in major currencies – is the commercial oxygen most digital-asset businesses never plan for until it is already failing them. Operating without reliable fiat rails exposes the business to frozen payables, stranded customer funds and, ultimately, regulatory scrutiny from the very regulators who issued the licence. This page maps the legal basis for banking access, the practical process of securing it, and the structural decisions that determine whether early-stage founders end up with a working payment stack or a string of rejection letters.
Why Banking Access Is a Legal Question, Not Just a Commercial One
Correspondent banking access for a virtual asset service provider (VASP – any business offering exchange, transfer, custody or related services in digital assets) is not merely a product relationship. It sits at the intersection of anti-money laundering law, payment regulation and the policies of the correspondent bank's own regulator. A VASP that cannot demonstrate a clean regulatory posture does not simply fail a commercial credit assessment; it fails a compliance gate that the bank's board-level risk committee has set. The FATF Recommendations, including Recommendation 15 on virtual assets and the Travel Rule (the obligation to pass originator and beneficiary data alongside a transfer), have hardened that gate considerably across every major financial centre.
In our practice, we see founders treat the licence application and the banking search as sequential steps. They are not. The jurisdiction of incorporation, the licence category, the AML programme design, the ownership structure and the client-money safeguarding model all feed directly into the bank's due diligence questionnaire. A structure built without the banking layer in mind will fail that questionnaire – and rebuilding it after rejection costs far more than designing it correctly from the start.
The cross-border dimension compounds the problem. A VASP may be licensed in one jurisdiction, bank in another, and serve clients in a third. Each link in that chain carries its own regulatory expectation. The FCA in the United Kingdom expects cryptoasset businesses to maintain a financial-crime framework that a UK correspondent bank can evidence to its own prudential supervisor. VARA in Dubai applies rulebook-level requirements on payment and transfer activity. Under MiCA, a CASP authorised in one EU member state and passporting across the bloc must meet ESMA-aligned AML standards that an EU correspondent will test independently. None of these regimes are interchangeable.
For a scoped review of your current structure and its banking prospects, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options.
What Actually Triggers a Correspondent Banking Ban?
A correspondent banking ban – the effective exclusion of a VASP from the interbank clearing network – typically results from a combination of structural, reputational and compliance factors rather than a single disqualifying event. Understanding the triggers is the first step to avoiding or reversing them.
The most common structural trigger is a mismatch between the licence the founder holds and the actual activity the business conducts. A payments company operating as an unlicensed exchange, or a custody provider accepting client orders without the requisite VASP registration, presents an unquantifiable risk to a correspondent. The bank cannot model the regulatory liability it is accepting. It declines.
A second trigger is an inadequate AML/KYC programme. Correspondent banks apply a layered due diligence model: their own compliance team reviews the VASP's policies, transaction monitoring procedures and sanctions screening logic. Programmes that are templated, untested or obviously bought off the shelf routinely fail this review. In our experience, the gap is usually not intent – it is operationalisation. The policy exists; the controls that implement it do not.
Third, and increasingly prevalent, is a category decision at the correspondent bank itself. Several major clearing banks have exited the crypto segment entirely, citing the cost of compliance monitoring relative to the revenue opportunity. This is a policy decision, not a judgment on the specific VASP. It cannot be cured by improving the VASP's documentation. The correct response is to identify which correspondent banks remain active in the segment and to approach them through the right channels – typically via an EMI (electronic money institution) or a licensed payment institution that already holds that correspondent relationship.
Geography adds another layer of complexity. A VASP with beneficial owners in jurisdictions that appear on FATF grey or black lists, or with a user base concentrated in high-risk markets, will face enhanced due diligence requirements. In some cases, a reorganisation of the ownership or operating structure – moving the operating entity closer to the target banking jurisdiction – is the most direct path forward.
How Does EMI Onboarding Work for VASPs?
EMI onboarding – the process by which a VASP establishes a payment relationship with an electronic money institution (an entity authorised to issue electronic money and provide payment services) – is the most practical route to fiat rails for most early-stage founders. A well-selected EMI holds its own correspondent banking relationships and extends those to clients through a managed-risk framework.
The onboarding process follows a structured sequence. The EMI's compliance team first conducts a high-level triage: jurisdiction of licence, activity type, transaction volume profile, AML programme summary. This takes days, not weeks. If triage passes, the EMI issues a detailed due diligence questionnaire covering corporate structure, UBO (ultimate beneficial ownership) disclosure, licence documentation, AML/KYC policies, sanctions screening procedures and source-of-funds analysis for the founders and key shareholders.
The depth of that questionnaire varies by the EMI's own regulatory position. An EMI authorised under the FCA regime or under the relevant EU payment-services framework faces its own supervisory examination. It has a direct commercial incentive to ensure its VASP clients do not become the compliance event that triggers regulatory action against the EMI itself. Founders who treat the questionnaire as a formality – submitting incomplete responses or documents that contradict each other – generate the refusal letters they are trying to avoid.
In a recent matter, an exchange at an early commercial stage had been declined by four EMIs in succession. Each refusal cited "incomplete AML documentation." The actual issue was that the exchange's UBO register listed a holding company rather than natural persons, and the AML policy's customer-risk-rating model had never been calibrated to the exchange's actual client base. We restructured the corporate disclosure, rewrote the risk-rating logic and prepared a tailored response to the next EMI's questionnaire. The exchange achieved onboarding within a matter of weeks of reapplying – without changing its licence jurisdiction or its business model.
The cross-border dimension here is acute. An EMI licensed in the EU – under MiCA's converging payment-services framework, or under a national authority transitioning to that regime – will apply FATF Travel Rule logic to transfers above the applicable threshold. A VASP that cannot demonstrate its own Travel Rule compliance infrastructure will not pass EMI onboarding regardless of how clean the rest of its documentation is.
What Fiat-Rails Options Exist for Early-Stage Founders?
Early-stage founders generally have three practical routes to fiat rails, each with different risk and cost profiles.
The first is a direct banking relationship with a bank that has a defined digital-asset client programme. These banks exist in Switzerland under FINMA oversight, in Singapore under the MAS Payment Services Act framework, in the UAE under VARA and ADGM/FSRA supervision, and in selected EU member states. The regulatory credibility of the licence the VASP holds, and the maturity of its compliance programme, determines access to this tier. Timelines are longer and due diligence is deeper, but the correspondent relationship is direct and therefore more stable.
The second route is the EMI intermediary model described above. It is faster and more accessible for early-stage businesses. The trade-off is that the VASP sits behind the EMI in the correspondent chain. If the EMI loses its own correspondent, the VASP's rails go with it. Concentrating 100 per cent of fiat flow through a single EMI is a risk management failure that we regularly identify in the structures of founders who come to us after a problem has materialised.
The third route is a payment licence obtained by the VASP itself. A VASP that holds both a VASP registration and a payment institution licence – whether in a jurisdiction like the UK under the FCA, an EU member state under the transitioning payment-services regime, or Singapore under the MAS Payment Services Act – can approach correspondents in its own right. This is a significantly higher regulatory bar, but it removes the dependency on an EMI intermediary and often unlocks better commercial terms with the correspondent.
If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Write to info@oboluslaw.com or map your options here.
Decision Matrix: Which Banking Route Fits Your Profile?
Selecting the right approach to correspondent banking access depends on the founder's regulatory position, commercial stage and risk tolerance. The analysis below is a working framework, not a universal prescription.
A pre-licence startup with an operating entity in formation and no existing AML programme should first determine the jurisdiction of licence before approaching any bank or EMI. The licence jurisdiction drives the compliance standard the EMI will expect. Approaching EMIs before the licence is issued produces refusals that can create a paper trail of rejections that complicates later applications. The correct sequence is: structure → licence application → AML programme build → EMI outreach.
An early-stage licensed VASP with a VASP registration in place and a compliant AML programme is the natural candidate for the EMI onboarding route. The priority is selecting an EMI whose own regulatory posture is aligned with the VASP's jurisdiction profile. An EU-licensed VASP should generally prioritise EMIs operating under the same or a closely comparable regulatory regime. Mismatches in regulatory expectation between the VASP's licence jurisdiction and the EMI's own regulator are a consistent source of friction that slows or prevents onboarding.
A scaling VASP with material transaction volumes – typically where the business has grown beyond the transaction-volume ceiling that most EMIs apply to their VASP clients – should assess whether a payment licence is the right next step. The cost and timeline of obtaining a payment institution licence varies by jurisdiction; the qualitative benefit is a direct correspondent relationship and the ability to manage payment risk in-house. In our practice, we map this threshold as a decision point when a client's EMI-based arrangement begins to generate reliability or cost concerns.
A multi-product VASP operating an exchange, a custody service and a payments function under the same group structure should in almost every case maintain separate regulated entities for the custody and payments functions. Regulators and correspondents treat ring-fencing as a proxy for operational and financial discipline. A single entity that attempts to hold all activities presents a consolidated risk profile that both the regulator and the correspondent bank will assess conservatively.
Common Mistakes That Block Correspondent Banking Access
The most damaging mistakes in the banking-access process are structural, not presentational. Founders frequently focus on the appearance of compliance – the policy documents, the organigram, the licence certificate – and underinvest in the underlying substance that a correspondent bank's compliance team is actually testing.
The first and most common mistake is treating the AML programme as a document exercise rather than an operational reality. A correspondent bank's due diligence team will ask how many SARs (suspicious activity reports) the VASP has filed, what its transaction monitoring alert rate is and how many cases it has escalated to its competent authority. A VASP that has been operating for eighteen months and reports zero alerts has not built a compliant programme. It has built a programme that produces no outputs – which is, to a correspondent bank, indistinguishable from having no programme at all.
The second mistake is inadequate UBO disclosure. The FATF recommendations require that beneficial ownership is traceable to natural persons at a defined ownership threshold. Complex multi-layer offshore structures that obscure the natural persons behind the VASP are a consistent trigger for refusal. The correspondent bank cannot satisfy its own regulatory obligations with opaque ownership. The solution is transparency, not complexity.
Third, founders regularly underestimate the importance of source-of-funds documentation for the founders themselves. The bank is onboarding the founder as much as the entity. A founder who cannot produce a clear and documented explanation of the personal capital used to establish the business – whether from prior employment, investment, an earlier exit or a loan – will fail the personal AML check regardless of how clean the entity-level documentation is.
Fourth, and specific to the cross-border context, founders frequently apply for banking access in a jurisdiction where they hold no substantive regulatory connection. A VASP licensed in the BVI under the VASP Act 2022 seeking a banking account in the EU without an EU-licensed entity or a nexus to an EU-regulated EMI will rarely succeed. The correspondent bank needs a regulatory anchor it can identify and reference in its own supervisory files.
How Client-Money Safeguarding Affects Your Banking Structure
Client-money safeguarding – the obligation to hold client funds in a manner that protects them from the insolvency of the VASP or EMI – is both a regulatory requirement under most applicable regimes and a practical determinant of banking structure. A VASP that holds client funds without a compliant safeguarding model is not merely in breach of its licence conditions; it is operating in a manner that no responsible correspondent bank will facilitate.
Under most flagship regimes, the safeguarding obligation requires client funds to be held in a segregated account at a regulated credit institution, or covered by an insurance or guarantee product that performs the equivalent function. The specific requirements – which account type qualifies, which credit institutions are acceptable, what the insurance or guarantee must cover – differ between the FCA's payment-services rules, the MiCA/EMT framework, and the approach taken by VARA or the AIFC/AFSA in the Gulf. We work through these differences with clients as part of structuring the banking layer, not as an afterthought to it.
The practical banking implication is that a VASP needs at least two accounts at a compliant credit institution: one for operating funds (the VASP's own money) and one or more for client funds (segregated and identifiable as such). Many early-stage founders operate from a single account until a regulator or an EMI flags the deficiency. By that point, the breach may already have generated a supervisory notice or a suspension of the EMI relationship.
The cross-border complication arises when the VASP operates across multiple jurisdictions, each with its own safeguarding standard. A CASP passporting under MiCA across EU member states is subject to ESMA's harmonised standards. The same group entity serving clients in Singapore under the MAS Payment Services Act framework must separately satisfy the safeguarding model applicable there. These are not interchangeable. We map this exposure as part of a cross-border banking review.
A Common Assumption About Offshore Licences
A common assumption among early-stage founders is that a single offshore VASP registration – in the BVI, the Cayman Islands or a comparable jurisdiction – is sufficient to serve clients globally and to access banking in any target market. This assumption, while understandable given the speed and cost advantage of those registrations, is commercially and legally incorrect.
An offshore registration establishes a regulatory baseline in the jurisdiction of issue. It does not confer the right to solicit clients in the EU, the UK, Singapore, Hong Kong or the United States. Each of those markets has its own VASP or CASP licensing regime. Operating into those markets from an offshore registration without the locally required authorisation exposes the VASP to enforcement action by the local regulator, injunctions on its payment rails, and account closures triggered by the local correspondent bank's own compliance team. The FCA, ESMA, MAS and the SFC all publish lists of unauthorised entities. Appearing on those lists destroys banking access faster than almost any other single event.
The practical answer is a licence stack rather than a single licence. The stack consists of the operating entity licence (which determines where the VASP can solicit), the custody licence where applicable, and the payment institution licence or EMI relationship that provides fiat rails. Designing that stack requires a clear view of the target client base, the target banking jurisdiction and the regulatory perimeter in each market. We map this structure before a client commits to an entity or a jurisdiction – not after the first bank account is closed.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital-Asset Businesses – full practice overview covering fiat rails, EMI selection and payment licence strategy across major hubs.
- PSP and Acquiring Agreements in France – jurisdiction-specific guidance on payment institution authorisation and acquiring arrangements under the French regulatory regime.
- MiCA Whitepaper Review in the British Virgin Islands – structuring and disclosure obligations for BVI-based token issuers managing MiCA compliance for EU-facing activities.
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily for three reasons: an inadequate AML/KYC programme that cannot satisfy the bank's own supervisory requirements, a mismatch between the licence held and the actual activity conducted, or a categorical decision by the correspondent bank to exit the digital-asset segment entirely. In each case, the root cause is a compliance risk the bank cannot quantify or manage within its own regulatory framework. Restructuring the compliance programme and selecting a correspondent with an active crypto-banking policy are the operative remedies.
How can a VASP onboard with an EMI?
A VASP onboards with an EMI by first completing the EMI's due diligence questionnaire, which covers corporate structure, UBO disclosure, licence documentation, AML programme, sanctions screening and transaction monitoring procedures. A complete, consistent and operationally substantiated submission is the differentiating factor between approval and refusal. Founders should also confirm that the EMI's own regulatory posture is compatible with the VASP's licence jurisdiction, and that the EMI's Travel Rule infrastructure can accommodate the VASP's transfer volumes before committing to the relationship.
What does client-money safeguarding require?
Client-money safeguarding requires a VASP or EMI to hold client funds separately from the entity's own operating funds, typically in a designated account at a regulated credit institution. The specific requirements – account type, eligible institutions, insurance or guarantee alternatives – vary between the FCA payment-services rules, the MiCA framework, VARA and the AIFC/AFSA regime, among others. A VASP operating across multiple jurisdictions must satisfy each applicable standard independently. A single operating account holding both client and firm funds is a common breach that triggers both regulatory and banking consequences.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – so the banking access problem is addressed in the structure, not after the first rejection. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory and Compliance Analyst – specialising in VASP licensing, AML programme design and correspondent banking strategy for early-stage and scaling digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.