EST · MMXXVI
Home/Services/Banking Payments Emi/Correspondent banking access for Established Operators
Banking, Payments & EMI Onboarding

Correspondent banking access for Established Operators

Correspondent banking access for Established Operators. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBO

Correspondent banking access is the structural pressure point that stops an otherwise compliant digital-asset business from moving fiat money at scale. For an established operator – a licensed exchange, custodian, payment institution or fund already past the formation stage – the risk is not theoretical. Banks terminate accounts, correspondents de-risk entire product lines, and the resulting gap between a valid licence and functional fiat rails can paralyze operations within days. In our practice, that gap is the single most common reason a well-structured business returns to counsel after launch.

The legal question here is specific: how does a licensed virtual-asset business build and defend correspondent banking access across the jurisdictions where it operates, banks, and holds client money? The answer turns on the intersection of AML/CFT (anti-money laundering and counter-financing of terrorism) compliance, the applicable VASP (virtual-asset service provider) regulatory regime, and the correspondent bank's own risk appetite – all of which vary by geography. This page maps the process, identifies the common failure points, and explains how OBOLUS structures the mandate for operators who have already built a regulated entity and need the fiat layer to match.

Why Correspondent Banking Access Fails for Crypto Operators

Correspondent banking failures for digital-asset businesses almost always trace to a compliance presentation problem, not a categorical prohibition. A correspondent bank is a financial institution that holds accounts for, and processes transactions on behalf of, another bank or payment institution – it sits between the licensed operator and the international payment system. Correspondent banks apply their own AML/CFT due-diligence overlays, which are often more stringent than the regulator's minimum. When those overlays are not met, the account is declined or terminated.

The standard FATF Recommendations – including Recommendation 15, which specifically addresses virtual assets and VASPs – require correspondent banks to assess their respondent's AML/CFT controls before establishing a relationship. A VASP that cannot demonstrate a functioning Travel Rule (the obligation to pass originator and beneficiary data with every qualifying transfer) programme, clear transaction-monitoring architecture, and auditable ownership structure will not survive that assessment. In our cross-border practice, we routinely see operators that hold valid VARA, MAS or FCA registrations but present to correspondent banks with documentation gaps that signal ongoing risk rather than managed risk.

The practical consequence is severe. Loss of a correspondent relationship can freeze inbound and outbound fiat flows entirely. For an exchange or custodian, that means client withdrawals stop. For an EMI-licensed payments firm, it means the core product fails. The timeline from notice to hard cutoff is often shorter than the time needed to find an alternative – which is why the work must be done before the relationship breaks down, not after.

Operating without a correspondent-ready compliance posture risks enforcement referrals, frozen rails, and reputational damage that makes the next application harder. If your current banking structure was assembled before your AML programme was fully operational, a structural review now is materially less expensive than a recovery exercise later. For a scoped assessment of your correspondent banking exposure, contact OBOLUS at info@oboluslaw.com.

What Is the Regulated Basis a Correspondent Bank Actually Checks?

A correspondent bank undertaking due diligence on a digital-asset respondent is verifying three things simultaneously: the existence and scope of the respondent's regulatory authorisation, the quality of its AML/CFT controls, and the nature of its underlying client activity. Each element maps to a different documentation set, and a weakness in any one of them can block the relationship.

On authorisation, the bank wants to see a licence or registration that is current, covers the specific activities the respondent is conducting, and was issued by a regulator the correspondent recognises. A MiCA CASP authorisation – the Crypto-Asset Service Provider authorisation under the EU's Markets in Crypto-Assets Regulation, supervised by national competent authorities and ESMA – carries significant weight with European correspondent banks because it signals a passportable EU-level standard. Similarly, a VARA licence in Dubai, a Payment Services Act authorisation from MAS in Singapore, or an FCA registration in the UK provides a recognised regulatory anchor. Offshore registrations in jurisdictions that do not publish enforceable AML/CFT rulebooks for VASPs generate immediate concern.

On AML/CFT, the correspondent bank will typically request: a current AML policy manual; evidence of a qualified Money Laundering Reporting Officer (MLRO); documented customer due-diligence and enhanced due-diligence procedures; transaction-monitoring system architecture; a Travel Rule solution name and counterparty coverage; and a sample suspicious-activity reporting log. The depth of the review scales with the volume and complexity of the account activity requested.

On client activity, the bank wants a clear narrative of who the respondent's clients are, what geographies they come from, what assets move through the account, and what the average and peak transaction volumes look like. Vague answers here are treated as evasion. Specific, documented, plausible answers – backed by client-base analytics and product descriptions – allow the correspondent's risk team to model the exposure and present an approval recommendation internally.

How EMI Onboarding Creates a Correspondent Banking Bridge

For many established operators, the fastest route to stable fiat rails is onboarding with a regulated EMI (electronic money institution) rather than approaching a tier-1 correspondent bank directly. An EMI holds its own banking licences and correspondent relationships; it can issue IBANs, process SEPA and SWIFT payments, and provide the operator with a compliant fiat account under a known regulatory umbrella. This is the dominant model for crypto exchanges and OTC desks seeking EU fiat access without a full credit institution licence.

The legal structure matters here. The operator's relationship with the EMI is governed by a master services agreement that sets out AML obligations on both sides, permitted transaction types, volume caps, and termination triggers. Under MiCA and the applicable EMI frameworks in EU member states, the EMI retains responsibility for its own compliance and will pass that responsibility contractually to the operator as a condition of onboarding. Negotiating those contract terms – particularly the indemnity provisions and the termination-for-convenience clause – is a material legal task that operators frequently undervalue.

Cross-border, the picture is more complex. An EMI authorised in one EU member state can passport SEPA reach across the EU, but its SWIFT correspondent access for non-euro payments depends on its own banking relationships. An operator with clients in Asia, the Middle East, and North America will need either an EMI that has negotiated multi-currency correspondent coverage or a second banking relationship in a non-EU jurisdiction – typically Singapore, the ADGM in Abu Dhabi, or the AIFC in Kazakhstan – to cover those corridors.

What Does the Correspondent Banking Onboarding Process Actually Look Like?

The onboarding process for correspondent banking access, approached correctly, follows a defined sequence: pre-application structuring, documentation assembly, regulatory narrative drafting, bank engagement, and ongoing relationship maintenance. Each stage carries its own failure modes.

Pre-application structuring means aligning the operator's entity, licence, and AML programme before the first approach. If the operating entity is domiciled in a jurisdiction the target bank treats as high-risk, or if the licence category does not cover the proposed activity, the application will fail regardless of documentation quality. In our practice, we begin every correspondent banking mandate with a jurisdiction-licence-activity mapping exercise to confirm that the structure being presented is coherent.

Documentation assembly is the stage operators most frequently underestimate. A complete correspondent banking package for a digital-asset respondent typically includes: certificate of incorporation and full corporate structure chart; current regulatory certificate with scope annotation; AML/CFT policy manual (current version, board-approved); MLRO appointment and CV; KYC/CDD procedures with a sample onboarding flow; Travel Rule solution certification; transaction-monitoring system documentation; audited or management accounts; a business narrative covering product, client type, geographic reach and volume projections; and personal data and source-of-wealth documentation for all beneficial owners above the applicable threshold. The threshold itself varies by jurisdiction and institution.

Regulatory narrative drafting is the element that most often determines the outcome. The bank's compliance team reads dozens of applications. A clear, structured narrative that explains the business model, anticipates the risk questions, and demonstrates proportionate controls is the difference between a smooth approval and an extended back-and-forth. We draft these narratives as legal counsel – not as marketing documents – which means they address risk directly rather than minimizing it. Banks trust operators who acknowledge the risk category and explain the mitigant.

The timeline from complete application to a functioning account varies. It is measured in weeks for well-prepared applications to established EMIs, and in months for direct correspondent relationships with tier-1 or tier-2 banks. Operators who approach without a complete package face iterative information requests that extend the timeline considerably and erode the bank's confidence in the process.

If a prior application stalled or an existing account was closed without explanation, a structural review of the documentation and narrative can identify the specific failure point and map a route back. To discuss that process, write to OBOLUS at info@oboluslaw.com or message us via t.me/oboluslaw.

The Cross-Border Reality: Where the Entity Sits Versus Where Banking Lives

The most persistent structural error in digital-asset banking is treating the operating jurisdiction and the banking jurisdiction as the same problem. They are not. A VARA-licensed exchange in Dubai may need correspondent banking through a Singapore MAS-regulated institution for Asian corridor flows, an EU EMI for European client settlements, and a US-regulated account for dollar clearing – three separate regulatory relationships, each with its own AML/CFT expectations and documentation requirements.

This fragmentation is not accidental. It reflects the risk-differentiation policies of correspondent banks, which assign country and sector risk scores independently. An operator in a jurisdiction with a strong VASP regime may still face restricted access if its client base is concentrated in geographies that its correspondent bank rates as elevated risk. The solution is not to obscure the client geography – that creates a compliance problem – but to demonstrate proportionate controls for each risk segment, supported by transaction-monitoring data.

The Travel Rule adds a specific cross-border layer. When a VASP sends funds to another VASP, the applicable regime requires originator and beneficiary information to travel with the transfer. The mechanics differ between jurisdictions – the FATF-aligned standard applies broadly, but the de-minimis threshold and technical implementation vary. An operator whose Travel Rule solution does not cover its actual counterparty universe is exposed both to regulatory breach and to correspondent bank termination, because the bank's own AML programme requires it to confirm that its respondents are Travel Rule-compliant for the corridors they operate.

In our cross-border practice, we map the full corridor picture – operating entity, client geography, banking jurisdiction, and counterparty VASP ecosystem – before advising on which correspondent relationships to pursue and in what sequence. Pursuing a banking relationship that cannot work structurally is a waste of time and, more importantly, it uses up the operator's credibility with institutions that may be approached again later.

Common Mistakes That Established Operators Make

Even experienced operators with mature compliance programmes make avoidable errors in the correspondent banking process. The most consequential are structural; they cannot be papered over with better documentation.

The first is presenting an incomplete licence. An operator with a custody licence that does not cover exchange activity, or a payments registration that excludes crypto-to-fiat conversion, is presenting a structure that does not match the proposed account activity. The correspondent bank's compliance team will identify the mismatch; the explanation then required is more damaging than the gap itself.

The second is a beneficial ownership chain that cannot be easily traced. Correspondent banks apply enhanced due diligence to beneficial owners above a defined threshold. A chain involving multiple holding companies in multiple offshore jurisdictions, without clear economic rationale, is a standard termination trigger. Simplifying the ownership structure before approach is always preferable to explaining it mid-process.

The third – and most fixable – is an AML programme that was built for regulatory approval rather than for operational credibility. A policy manual that describes procedures no one follows, or a transaction-monitoring system that generates alerts that are not actioned, is visible to an experienced compliance reviewer. The programme must be operational, not decorative.

The fourth is approaching too many institutions simultaneously. Banks talk to each other. Multiple simultaneous applications, particularly if any result in declines, can generate adverse intelligence that follows the operator through subsequent approaches. A sequenced strategy, with a primary target and identified alternatives, is materially better than a broadcast approach.

Decision Matrix: Which Banking Route for Which Operator Profile

Not every established operator needs the same banking solution. The right route depends on the operator's licence category, geographic reach, client base, and volume profile. The following outlines the key decision branches.

Profile A – EU-licensed CASP or EMI seeking euro and multi-currency fiat rails. The primary route is onboarding with a regulated EU EMI that has demonstrated SEPA and SWIFT coverage and an established crypto-business client base. The timeline is typically a matter of weeks for a well-prepared application. The key risk is volume cap provisions in the master services agreement; these require careful negotiation upfront.

Profile B – VARA-licensed Dubai operator seeking multi-corridor access. The combination of a DIFC or ADGM account for regional flows and an EU EMI for European settlements is the most common structure we see. Adding a Singapore MAS-regulated account for Asia-Pacific corridors provides a complete three-pillar setup. The timeline across all three relationships, run in parallel with a coordinated documentation package, is typically measured in months rather than weeks. The key risk is sequencing – a bank that sees a declined application from another institution in the same period will apply heightened scrutiny.

Profile C – UK FCA-registered operator with global client reach. The FCA's MLR registration provides a strong credibility anchor for UK and European EMI onboarding. For non-sterling corridors, the operator typically needs a separate non-UK banking relationship. The financial-promotion rules that apply under the FCA regime create an additional documentation layer; the operator must demonstrate that its marketing to UK clients complies, as this affects the correspondent bank's assessment of the overall compliance posture.

Profile D – BVI or Cayman-domiciled fund or OTC desk. These operators face the most restricted access. The VASP Act regimes in both jurisdictions are recognised by informed correspondent banks, but the broader market perception of offshore domicile increases the documentation burden significantly. Onboarding through an EMI rather than direct correspondent banking is almost always the preferred route; the EMI's own risk framework absorbs some of the jurisdictional premium. The timeline is typically longer, and the volume profile must be clearly documented to support the account's commercial rationale.

In each profile, a micro-matter from our practice illustrates the practical reality. In a recent mandate, an exchange operator with dual licences in an EU member state and a Gulf free zone had its primary EMI relationship terminated following a routine AML review. The operator approached us after the termination notice. We identified that the termination trigger was a Travel Rule gap in the operator's Asia-Pacific transfer flow, not the core European business. We restructured the Travel Rule solution documentation, prepared a corrective action narrative, and supported the operator's engagement with two alternative EMIs, one in an EU jurisdiction and one in the AIFC. The replacement relationships were operational within a commercial timeframe, and the operator avoided the client-impact scenario it had anticipated.

What Does Client-Money Safeguarding Require in This Context?

Client-money safeguarding is a distinct legal obligation that sits alongside, and interacts with, correspondent banking access. Under most flagship VASP and payment institution regimes – including MiCA's EMI provisions, the MAS Payment Services Act framework, and the FCA's client-asset rules – client funds must be segregated from the operator's own funds and held in a manner that protects them in an insolvency. The correspondent banking structure must be built to support that segregation, not to undermine it.

In practice, this means that the accounts through which client fiat money flows must be designated and structured in a way that the applicable regime recognises as compliant segregation. A single pooled account that mixes client and operational funds is non-compliant in virtually every licensed regime and is a specific termination trigger for correspondent banks that understand the sector. The correct structure uses a nominated client-money account, held at a credit institution or EMI, with a formal trust or safeguarding declaration that aligns with the applicable regime's requirements.

Cross-border, the safeguarding structure must be coherent across all the jurisdictions where client money is held. If an operator holds client funds in accounts across three jurisdictions, the safeguarding declarations must be effective under the law of each jurisdiction, and the correspondent bank or EMI in each jurisdiction must have acknowledged the nature of the account. This is a legal drafting task; it is not resolved by an AML policy alone.

A common assumption in this area is that the operator's home-jurisdiction safeguarding structure automatically satisfies the requirements of the correspondent bank's jurisdiction. It does not. Each banking jurisdiction applies its own rules for what constitutes effective segregation, and a safeguarding structure that is entirely compliant in one regime may not achieve the same legal effect elsewhere. We address this systematically in the documentation stack for every multi-jurisdiction banking mandate.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily for two reasons: a perceived mismatch between the operator's AML/CFT programme and the bank's own risk standards, and a general de-risking policy that categorically exits entire sectors regardless of individual compliance quality. Specific triggers include Travel Rule non-compliance, inadequate transaction monitoring, unclear beneficial ownership, and client-base geographies the bank rates as elevated risk. A well-documented compliance posture substantially reduces the categorical risk, though it does not eliminate it entirely where the bank has made a sector-wide policy decision.

How can a VASP onboard with an EMI?

A VASP onboards with an EMI by presenting a complete application package that covers its regulatory authorisation, AML/CFT programme, Travel Rule solution, corporate structure, and business narrative. The EMI applies its own KYC and risk-assessment process to the VASP as a business client; this is materially more involved than standard business account opening. Negotiating the master services agreement – particularly volume caps, permitted activities, and termination provisions – is a critical step that follows the compliance review. Legal counsel during both the documentation stage and the contract negotiation improves both the approval rate and the contractual outcome.

What does client-money safeguarding require?

Client-money safeguarding requires that client fiat funds be held separately from the operator's own funds in a designated account at a recognised credit institution or EMI, with a formal trust or safeguarding declaration effective under the applicable law. The requirement applies under most regulated VASP and payment institution regimes, including MiCA's EMI provisions, the MAS Payment Services Act framework, and the FCA's client-asset rules. In a multi-jurisdiction structure, the safeguarding declaration must be legally effective in each jurisdiction where client money is held – a cross-border drafting task that cannot be resolved by policy documentation alone.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP regulatory compliance and correspondent banking access across EU, Gulf and Asia-Pacific regimes.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours