EST · MMXXVI
Home/Services/Banking Payments Emi/Correspondent banking access from a Cross-border Perspective
Banking, Payments & EMI Onboarding

Correspondent banking access from a Cross-border Perspective

Correspondent banking access from a Cross-border Perspective. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk

For a digital-asset business that has cleared its licensing hurdle, the next crisis arrives quietly: a correspondent bank declines to settle a wire, an EMI (electronic money institution) suspends an account without notice, or a payment processor exits the crypto vertical entirely. The legal question is not abstract. Without stable fiat rails – the conventional-currency settlement channels that connect a crypto business to the traditional financial system – a licensed exchange cannot fund client accounts, a custodian cannot receive subscription proceeds, and a token issuer cannot distribute proceeds to contributors. Correspondent banking access is, in practice, the operational nerve of a cross-border digital-asset business.

This page sets out the regulatory basis for correspondent relationships, the onboarding process that actually works, the cross-border structural choices that determine whether access is stable or fragile, and the common mistakes that erode banking even after a licence is in hand.

Why Correspondent Banking Is the Operational Nerve of a Crypto Business

Correspondent banking is the mechanism by which a local bank, custodian or EMI settles payments in a currency or market where it has no direct presence, by routing through a larger institution – the correspondent – that holds an account on its behalf. For a VASP (virtual asset service provider), that chain runs from the client's commercial bank, through one or more correspondent institutions, and finally into the VASP's account at a payment institution, EMI, or direct bank relationship. Each link in the chain carries its own compliance gate.

The challenge is structural. A correspondent bank takes on indirect exposure to every counterparty its respondent serves. When the respondent is a VASP, the correspondent is effectively underwriting the VASP's entire client base from an AML and sanctions perspective. Regulators in the major hubs – FinCEN in the United States, the FCA in the United Kingdom, and national competent authorities implementing the MiCA (Markets in Crypto-Assets Regulation) regime in Europe – all require correspondents to conduct enhanced due diligence on respondents with crypto exposure. That enhanced diligence gate is where most crypto businesses encounter friction.

We regularly advise businesses that arrive at this point having treated banking as an afterthought. The structure was built around the licence. The banking was assumed to follow. It rarely does without deliberate preparation.

The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. For a scoped assessment of your correspondent banking position, contact OBOLUS at info@oboluslaw.com.

What Is the Regulated Basis for Correspondent Relationships?

Correspondent banking for VASPs sits at the intersection of three regulatory layers, each of which must be satisfied before a relationship opens. First, the VASP itself must hold the appropriate licence or registration in its operating jurisdiction. Second, the correspondent must satisfy its own regulator that its respondent relationships – including any with crypto-exposed entities – meet the required AML/CFT standard. Third, the Travel Rule (the obligation under FATF Recommendation 15 to pass originator and beneficiary data with a virtual-asset transfer) creates an additional data-sharing requirement that sits alongside the conventional SWIFT wire instructions.

Under the FATF Recommendations, correspondent banking relationships with respondents in jurisdictions that do not adequately supervise VASPs carry heightened risk. This means the jurisdictional choice of the VASP entity is directly legible to the correspondent's compliance team. A VASP registered in a jurisdiction where the regulator has a strong AML supervisory record – MAS in Singapore, FINMA in Switzerland, or a CASP (Crypto-Asset Service Provider) authorised under MiCA – will generally receive a materially different compliance response than one registered in a jurisdiction with limited supervisory infrastructure.

The Payment Services Act regime in Singapore, the VARA regime in Dubai, and the ADGM/FSRA framework in Abu Dhabi each carry their own correspondent-bank recognition profiles. In our practice, we have seen meaningful differences in the speed and ease of onboarding depending solely on which jurisdiction the VASP entity sits in – not on the quality of the underlying compliance programme.

How Does De-Risking Affect Crypto Businesses Specifically?

De-risking – the practice by which a bank exits entire client categories rather than managing risk at the individual-client level – is the primary structural threat to correspondent banking access for crypto businesses. It is not the same as a compliance failure by the VASP. A bank may close an account for a well-run, fully licensed exchange simply because its board has decided that the reputational and regulatory cost of maintaining crypto exposure outweighs the revenue. No licensing milestone prevents that decision.

The practical effect is that access depends on the institutional profile of the correspondent as much as on the VASP's own compliance posture. Certain categories of institution – specialist crypto-friendly banks, EMIs with digital-asset policies embedded in their onboarding frameworks, and payment institutions operating under MiCA in EU jurisdictions – have built business models around serving VASPs and are structurally less likely to de-risk the vertical.

The cross-border dimension adds further complexity. A VASP that holds its operating licence in one jurisdiction and its principal banking relationship in another creates a jurisdictional mismatch that correspondent compliance teams flag immediately. A Lithuanian CASP banking through a Swiss correspondent whose parent correspondent is a US clearing bank faces three separate compliance assessments, each governed by a different regime. OBOLUS maps that chain before onboarding begins.

Operators we advise routinely underestimate how much of their onboarding narrative must be prepared in advance: corporate structure charts, ownership and control disclosures, AML programme documentation, Travel Rule implementation evidence, and a clear articulation of the product and user base. The correspondent's compliance team is not a regulator. They are making a commercial risk decision. The documentation must make that decision easy.

How Can a VASP Successfully Onboard with an EMI?

EMI onboarding for a VASP follows a distinct sequence, and most refusals occur at one of three predictable points in that sequence. An EMI authorised under the EU's E-Money Directive – or its national equivalents in the UK and other jurisdictions – is itself subject to AML supervision and must apply its own due diligence to every business client. The VASP is not merely an applicant; it is a risk exposure for the EMI.

The first friction point is product classification. If the VASP's primary activity involves exchanging virtual assets for fiat, the EMI must understand whether that activity is licensed in the VASP's home jurisdiction and what AML obligations attach. An EMI that cannot map the VASP's licensed perimeter to its own risk framework will decline rather than investigate further. The solution is a concise, accurate licence summary prepared for the EMI's compliance team – not the full regulatory text, but a document that answers the questions the team will ask.

The second friction point is ultimate beneficial ownership. VASPs with complex multi-tier holding structures, nominee arrangements, or beneficial owners in jurisdictions on enhanced-monitoring lists will face extended review timelines. In our cross-border practice, we prepare ownership disclosure packages that trace the control chain to natural persons in a format that matches the EMI's KYB requirements, not the VASP's internal records.

The third friction point is client-money safeguarding. An EMI that holds fiat on behalf of the VASP's clients must satisfy itself that the VASP's client-money obligations are met. The applicable safeguarding regime – under the E-Money Directive in the EU, the FCA's payment services rules in the UK, or equivalent provisions elsewhere – requires that client money is segregated, and the EMI needs evidence that the VASP's structure supports that segregation. Failing to demonstrate this at the outset is among the most common reasons for onboarding failure.

What Does the Cross-Border Banking Stack Actually Look Like?

Most digital-asset businesses operate across at least three jurisdictions simultaneously: the jurisdiction where the operating entity is licensed, the jurisdiction where the principal banking or EMI relationship is held, and the jurisdictions where the end clients are located. Each leg of that structure creates separate regulatory obligations, and the interactions between them determine whether the correspondent chain is stable.

Consider a CASP authorised in an EU member state that serves institutional clients in the Gulf and holds its primary banking relationship with a Singapore-regulated institution. The CASP's MiCA authorisation governs its EU-facing obligations and gives it EU passporting rights. The Singapore payment institution relationship is governed by the Payment Services Act. The Gulf-side client flows may engage VARA or ADGM/FSRA notification obligations depending on the nature of the services offered. Each of those three nodes in the structure must be coherent as a whole – not just individually compliant.

The cross-border banking stack should be designed, not assembled opportunistically. In our practice, we map the full chain: entity jurisdiction, banking jurisdiction, client jurisdiction, and the correspondent chain that connects them. That mapping identifies structural weaknesses before they cause account closures or enforcement scrutiny.

A common mistake is treating the banking relationship as the last step in the setup process. By the time the structure is set and the licence is in hand, the leverage to choose the right banking jurisdiction – and to negotiate onboarding terms with an EMI or correspondent – is at its highest. After the first account closure, the options narrow.

If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Write to OBOLUS at info@oboluslaw.com to discuss a remediation assessment.

Which Banking Profile Fits Which Operator?

Different operator profiles require different approaches to the correspondent relationship, and treating all crypto businesses as a single category is itself a structural error.

An exchange or trading platform with retail clients and high transaction volumes requires a banking partner with automated AML monitoring, Travel Rule compliance infrastructure, and a high-volume transaction processing capacity. The risk profile is different from a custodian that processes lower volumes but holds large balances. For this profile, an EMI with a dedicated crypto vertical and a direct correspondent relationship with a major clearing bank is typically the more durable solution than a smaller niche institution without that correspondent standing.

A token issuer conducting a regulated offering requires banking access for a relatively defined period – the subscription and distribution window – and the compliance burden is concentrated in the KYC/AML documentation for the offering itself. The banking question here is less about ongoing transaction volume and more about institutional credibility: the correspondent needs to be comfortable with the nature of the instrument and the investor base before the offering opens.

A fund or institutional vehicle with a small number of high-value counterparties can often access correspondent relationships through prime brokerage or institutional banking channels that are not available to retail-facing platforms. The compliance gate is still present, but the diligence is conducted at a different level of granularity and with a different risk appetite on both sides.

In each case, the entry point matters. A VASP that approaches onboarding with a complete compliance package – licence documentation, AML programme, Travel Rule implementation evidence, and a clear product narrative – will consistently achieve better outcomes than one that provides documentation reactively. The correspondent's first impression of the VASP's compliance culture is formed before the relationship opens.

A Practical Illustration

In a recent structuring matter, a payments company holding a licence in a mid-tier EU jurisdiction sought to onboard with two EMIs simultaneously in order to diversify its fiat rail exposure. Both EMIs declined at the initial stage, citing insufficient documentation of the ultimate beneficial ownership structure and an inability to verify that the company's AML programme addressed the Travel Rule obligations that applied to its cross-border transfer volumes. We restructured the ownership disclosure package, prepared a Travel Rule implementation memorandum tailored to the EMI's compliance template, and coordinated re-engagement with both institutions. One onboarding was completed within a matter of weeks; the second required a structural amendment to the client-money segregation arrangement before the EMI would proceed. The company subsequently held diversified fiat rails with two regulated institutions across two EU jurisdictions.

What Are the Most Common Banking Mistakes for VASPs?

The most frequent failure mode is building the operating structure for the licence and only then asking what the banking requires. By that point, the entity structure, the jurisdiction, and the ownership presentation are fixed – and if they are not banking-friendly, remediation is expensive.

A related error is relying on a single banking relationship. Correspondent banking is a commercial relationship, not a utility. An EMI can terminate for business reasons on contractual notice. A correspondent bank can exit the crypto vertical as a matter of group policy. A business that has built its settlement infrastructure on one fiat rail is not one compliance decision away from a banking relationship – it is one business decision by its counterparty away from operational failure.

A common assumption is that a single offshore licence is sufficient to serve a global client base. This is not accurate. A VASP licensed in one jurisdiction that actively solicits or services clients in another – without the required local registration, notification, or licence – faces enforcement exposure in the client's jurisdiction and creates a compliance problem for any correspondent or EMI that has mapped the actual user base. The licence must cover the geography of the business, not just the geography of the entity. Correspondents and EMIs increasingly verify this as part of their onboarding diligence.

Finally, VASPs frequently underestimate the ongoing compliance burden of maintaining a correspondent relationship. Onboarding is a process. Maintenance is a posture. Annual AML reviews, periodic KYB refresh requests, Travel Rule audit queries, and transaction monitoring enquiries are all features of a live correspondent relationship. The businesses that retain stable banking are those that treat compliance as an operational function, not a one-time event.

Self-Assessment: Is Your Business Banking-Ready?

Before approaching an EMI or correspondent bank, a VASP should be able to answer the following questions affirmatively. First, does the entity hold a valid licence or registration that covers the services it actually provides, in each jurisdiction where it operates? Second, is the ultimate beneficial ownership structure documented and capable of being disclosed clearly, without nominee layers that cannot be explained? Third, does the AML programme address the Travel Rule obligations that apply to the VASP's transaction types and volumes? Fourth, is client money segregated in a way that satisfies the safeguarding requirements of the prospective banking jurisdiction? Fifth, is there a clear, written account of the product, the user base, and the geographic footprint that the compliance team at the institution can work from?

A business that cannot answer all five questions affirmatively is likely to face onboarding friction. The solution is to address each point before approaching the institution – not to present incomplete documentation and supplement it reactively during the review process.

We map the licence stack across operating, custody, and payment layers before a client commits to a structure. That mapping identifies the banking dependencies that the licence choice creates and the steps needed to satisfy them.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily through de-risking – a commercial decision to exit an entire client category rather than manage individual-account risk. The triggers include insufficient AML documentation, unverifiable beneficial ownership, a licence that does not cover the VASP's actual activity, or a group-level policy change by the correspondent bank. A well-run compliance programme reduces the risk but cannot prevent a policy-driven exit. Structural diversification across multiple institutions and jurisdictions is the more durable protection.

How can a VASP onboard with an EMI?

Successful EMI onboarding requires three elements prepared in advance: a clear licence summary that maps the VASP's regulated perimeter to the EMI's risk framework; a full beneficial ownership disclosure tracing control to natural persons; and evidence that the AML programme addresses the Travel Rule obligations applicable to the VASP's transaction types. Presenting incomplete documentation and supplementing reactively is the most common cause of avoidable delays. A pre-submission compliance review significantly improves the probability of a first-pass approval.

What does client-money safeguarding require?

Client-money safeguarding requires that funds belonging to clients are held separately from the firm's own funds, in a manner that protects those funds in the event of the firm's insolvency. The specific requirements vary by jurisdiction and by the nature of the licence held – the E-Money Directive regime in the EU, the FCA's payment services framework in the UK, and equivalent regimes elsewhere each set out the applicable segregation, reconciliation and record-keeping obligations. An EMI will require evidence that the VASP's structure supports the relevant safeguarding standard before it will hold fiat on behalf of the VASP's clients.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, banking and payment stack before clients commit to a structure – and we coordinate remediation where an existing structure has created banking friction. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP licensing, correspondent banking onboarding and cross-border regulatory compliance for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours