For digital-asset businesses, access to correspondent banking – the network of interbank relationships that moves fiat currency across borders – is not a commercial convenience. It is the operational foundation on which licensing value, client settlement and business continuity rest. When that access is withdrawn, frozen or never secured, the entire entity stalls. A correspondent banking relationship (the arrangement by which a respondent bank holds accounts and processes cross-border payments on behalf of another institution) is typically the last piece of the infrastructure stack to be built and the first to fail. In our practice, we see the consequences of that sequence regularly: a licensed exchange or custody provider that has invested months in regulatory approval discovers that no bank in a target market will accept the resulting legal entity as a client.
The legal question is not simply "which bank will take us?" That is a commercial question. The legal question is whether the corporate structure, the licence profile, the AML controls and the contractual documentation are positioned correctly to survive a compliance review at a major clearing institution. Correspondent banking access for digital-asset firms is a structured legal problem, not a placement exercise. This page sets out how OBOLUS approaches that problem and the common structural reasons it arises.
Why Correspondent Banking Access Fails for Digital-Asset Firms
Correspondent banking access fails for digital-asset firms at the compliance review stage, not at the commercial negotiation stage. A clearing bank's financial crime compliance team evaluates the respondent institution against a set of criteria that most crypto-native entities have not been structured to satisfy. The result is a decline or, more commonly, a prolonged onboarding review that expires without a decision.
The core issue is risk categorisation. Correspondent banks treat digital-asset businesses as high-risk financial institutions by default. That categorisation triggers an enhanced due diligence process that examines the entity's regulatory status, the jurisdictions it serves, the nature of its clients, the quality of its AML and Travel Rule (the obligation to transmit originator and beneficiary data with a value transfer) compliance programme, and the source of its operating capital. A firm that cannot present satisfactory answers to all five dimensions is unlikely to be onboarded, regardless of how many licences it holds.
In our cross-border practice, three structural failures account for the majority of declined applications. First, the operating entity is licensed in one jurisdiction but serves clients or holds assets across many others – a profile that raises passporting and unregistered-activity concerns in the clearing bank's review. Second, the AML programme is designed to satisfy the licensing regulator but not the correspondent bank's own internal standards, which are frequently higher. Third, the corporate structure creates opacity: ultimate beneficial ownership is difficult to trace, or the entity's relationship to a group structure involving offshore holding companies has not been clearly documented.
OBOLUS maps the specific compliance gap before any placement approach is made. Addressing that gap first – through structural amendment, documentation uplift or policy revision – is the only reliable way to achieve a durable banking relationship rather than a temporary account that is closed at the next periodic review.
Contact OBOLUS for a scoped assessment of your banking situation. The process above describes the standard path, but your specific entity profile, licence category and user base change the analysis entirely. Reach us at info@oboluslaw.com or map your options.
The Regulated Basis for Fiat Rails: What a Bank Actually Requires
A correspondent bank will not process payments for a digital-asset business that lacks a legally adequate regulatory footprint in the jurisdictions where it operates. The licensing requirement is not a formality – it is the predicate for the entire compliance analysis.
The relevant regime depends on the activity. An exchange or custodian operating in the European Union requires authorisation as a CASP (Crypto-Asset Service Provider) under MiCA, the Markets in Crypto-Assets Regulation supervised by ESMA and national competent authorities. A payment-focused entity handling fiat on-ramps and off-ramps may additionally require a payment institution licence or an e-money institution authorisation in the relevant member state. In the United Arab Emirates, the VARA regime governs exchange and transfer activity in mainland Dubai; ADGM and the FSRA cover equivalent activities in the Abu Dhabi financial free zone. In Singapore, the Monetary Authority of Singapore (MAS) administers the Payment Services Act, under which a Digital Payment Token service licence is the operative instrument for crypto exchange and transfer services.
Each of those licensing regimes carries conduct-of-business obligations that a correspondent bank's compliance team will read against its own correspondent banking policy. The bank is looking for evidence of ongoing regulatory supervision, a functioning AML and KYC programme aligned with FATF Recommendation 15, and a Travel Rule compliance solution that covers cross-border value transfers. It is also looking for evidence that the entity is not a shell – that it has substance in the jurisdiction of licensing, with qualified personnel and operational infrastructure.
The interaction between the licensing regime and the correspondent banking review is a key area of our advisory work. We regularly advise operators on the gap between what their current licence requires and what a major clearing institution will expect to see, and on the steps needed to close that gap before the banking approach is made.
Operators targeting the EU should also note that MiCA's passporting mechanism – under which a CASP authorised in one EU member state may operate across the EEA – creates a specific opportunity for correspondent banking, because it allows a single regulatory relationship to support multi-market fiat operations. Getting the passporting notification right from the outset is therefore a material component of the banking strategy.
What Does the Process and Timeline Look Like?
The correspondent banking onboarding process for a digital-asset firm follows a structured sequence that, in our experience, typically spans several weeks to several months depending on the clearing institution and the completeness of the initial submission.
The process begins with a pre-submission diagnostic: an audit of the entity's regulatory status, corporate structure, UBO documentation, AML programme and existing correspondent relationships. This is not optional preparation – it is the stage at which the most common structural problems are identified and resolved before they become reasons for decline. A declined application at a tier-one correspondent bank is a material reputational event that narrows the field of available partners.
The second stage is documentation assembly. A correspondent banking application for a digital-asset firm typically requires the following categories of material: corporate constitutional documents and group structure chart with beneficial ownership to the natural-person level; regulatory licences and any supervisory correspondence demonstrating good standing; an AML/CFT policy and procedure manual; a sample of transaction monitoring and sanctions screening logs; a Travel Rule compliance statement; and audited financial statements. The depth of each document set will vary by institution, but the categories are consistent across the major clearing banks.
The third stage is the compliance review itself. This is conducted by the prospective correspondent's financial crime team. It is common for a digital-asset client to receive detailed questionnaires – in the industry often called CBOC (Correspondent Bank Onboarding Checks) or enhanced due diligence questionnaires – that probe the nature of the entity's own client base, its geographical reach and its handling of high-risk client profiles. The quality of the responses to those questionnaires is frequently the determinative factor in the outcome.
Timelines vary significantly. A well-prepared submission to an institution that has an established digital-asset banking programme may resolve in a matter of weeks. A submission to an institution that is building its digital-asset framework for the first time will typically take longer, and the outcome is less predictable. We advise clients to run parallel approaches to multiple institutions rather than sequencing them, and to calibrate expectations accordingly.
If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. We have seen accounts closed at periodic review for reasons that were entirely remediable – an AML policy that had not been updated following a licensing change, or a corporate structure that had evolved without updating the bank's KYC file. Reach us at info@oboluslaw.com or map your options.
Is EMI Onboarding a Viable Alternative to Correspondent Banking?
For many digital-asset firms, onboarding with a licensed EMI (electronic money institution) is a faster and more accessible path to fiat rails than direct correspondent banking, though it carries distinct constraints that must be understood before the structure is committed.
An EMI is authorised to issue electronic money and to provide payment services under the applicable payment services regime – in the EU, under the framework derived from the Payment Services Directive and the Electronic Money Directive, now transitioning progressively under PSD3. An EMI can provide an IBAN-like account, process SEPA transfers and, in some cases, provide SWIFT access through its own correspondent relationships. For a digital-asset business that needs to receive and send EUR, GBP or other fiat currencies on behalf of clients, an EMI relationship can substitute for a direct bank account in many operational scenarios.
The critical legal caveat is client money safeguarding. An EMI is required to safeguard client funds – to hold them in a segregated account at a credit institution or in low-risk liquid assets – and cannot use those funds in its own operations. That obligation mirrors, in part, the custody and segregation obligations that apply to licensed VASPs for digital assets. A digital-asset business that passes client fiat through an EMI account must understand both the EMI's safeguarding model and how that model interacts with its own client money obligations under its VASP or CASP licence. Misalignment creates regulatory and insolvency risk.
In a recent engagement, a payment company that had obtained a CASP authorisation in an EU member state was using an EMI for its fiat settlements but had not mapped the safeguarding obligations correctly across the two layers. The firm's own licence required segregation of client funds; the EMI's safeguarding model was adequate on its face, but the contractual arrangements did not clearly establish that the funds were client money for insolvency purposes. We restructured the contractual and operational layer to align both regimes, and the firm was able to demonstrate full compliance at its next supervisory review.
EMI onboarding also typically has a shorter decision timeline than correspondent banking – measured in weeks rather than months – making it an effective interim solution while a direct banking relationship is developed in parallel. However, EMIs serving digital-asset clients face their own banking risk: their own correspondent relationships can be withdrawn, which would render the EMI unable to operate. Selecting an EMI with a diversified and stable correspondent banking stack is therefore part of the due diligence exercise.
Cross-Border Structure and the De-Risking Problem
The cross-border reality of digital-asset banking is that correspondent banks and EMIs routinely apply a policy of de-risking – the withdrawal of banking services from entire categories of client rather than from individual clients assessed on their own facts. For digital-asset businesses, de-risking is an existential operational risk, and the structural response to it is a key element of our advisory mandate.
De-risking at the correspondent level is driven by the asymmetry between the compliance cost of monitoring a high-risk category of client and the revenue that category generates. A clearing bank that handles global payment flows can absorb the reputational and regulatory risk of a crypto exchange only if the compliance programme around that exchange is demonstrably strong and the revenue justifies the cost. For small to mid-size digital-asset operators, that calculus frequently does not work in their favour at a tier-one institution. The practical response is a diversified banking strategy: multiple relationships across multiple jurisdictions, structured to ensure that no single correspondent failure grounds the business.
For a business sitting between the EU and a Gulf hub – licensing in Malta under the MFSA, for example, with operations channelled through a VARA-licensed entity in Dubai – the legal question turns on which entity holds which banking relationship and how the fiat flows between them are structured. A holding company, an operating company and a custody entity may each require separate banking and payment relationships, and the tax and regulatory implications of those flows must be designed into the structure from the outset.
We regularly advise on the interaction between the licensing stack, the banking layer and the tax position across these multi-hub structures. The practical output is a structure that is defensible in each jurisdiction of operation, that presents a clean compliance story to each banking partner, and that is designed to survive the loss of any single banking relationship without material disruption to operations.
Jurisdictions where digital-asset banking infrastructure has developed most substantively include certain EU member states operating under MiCA, the AIFC in Kazakhstan under the AFSA, and Singapore under MAS supervision. The BVI FSC and CIMA regimes in the Cayman Islands remain relevant for fund and holding structures, though the banking environment for those entities continues to tighten under FATF pressure. Operators building a multi-jurisdiction structure should map the banking environment in each proposed jurisdiction before committing to a corporate form, not after.
What Are the Most Common Structural Mistakes?
The most common structural mistake in correspondent banking access for digital-asset firms is sequencing the banking strategy after the licensing strategy rather than in parallel with it.
The licence is obtained, the technology platform is built, and the banking approach is made last – at which point the corporate structure, the entity profile and the jurisdictional footprint have already been fixed in ways that may make banking materially harder or impossible. A limited company registered in a jurisdiction with a weak correspondent banking environment, operating under a licence category that does not clearly resolve the AML-compliance questions a bank will ask, with a shareholder structure that takes more than a few steps to reach the natural-person UBO – that combination produces predictable difficulties.
A second common mistake is treating the AML programme as a regulatory deliverable rather than a banking deliverable. Most licensing regulators require an AML and KYC policy; most do not audit it against the standards that a correspondent bank's compliance team applies. The result is a policy that satisfies the regulator but fails the bank. The gap is usually not about intent – it is about the level of operational specificity in the documentation. A bank wants to see transaction monitoring thresholds, escalation procedures, named compliance officers and evidence that the policy is actually implemented.
A third mistake – one we see particularly in firms that have scaled quickly – is failing to update the banking file when the business model changes. An entity that was onboarded as a custody provider and has since added exchange or lending activity has a materially different risk profile from the one the bank originally assessed. The obligation to notify the bank of material changes is both contractual and regulatory in most jurisdictions, and failure to do so creates a debanking event risk at the next periodic review.
Which Banking Strategy Fits Your Profile?
The appropriate banking and payment infrastructure strategy depends on the operator's specific profile – its activity, its licence status, its geographical footprint and its stage of development. The following decision branches describe the principal paths we advise on in practice.
Profile A – Early-stage operator, single jurisdiction, seeking initial fiat access. The appropriate instrument is typically an EMI relationship, selected after due diligence on the EMI's own banking stack and safeguarding model. The priority is to establish clean, documented fiat rails quickly enough to support the licensing process itself, which often requires evidence of banking access. The risk at this stage is selecting an EMI that will itself face banking difficulties as the operator's volumes grow and its client profile becomes more complex.
Profile B – Licensed operator, multi-market activity, seeking correspondent banking. The appropriate path is a structured pre-submission process: a compliance gap analysis, AML programme uplift, UBO documentation review, and parallel approaches to multiple correspondent institutions across two or three jurisdictions. The risk at this stage is concentrating on a single institution and treating the process as a commercial negotiation rather than a regulatory one.
Profile C – Scaled operator, experiencing de-risking or account closure. The priority is a rapid structural diagnostic to identify the compliance-specific reason for the closure or the de-risking event, followed by a remediation plan before the next banking approach is made. A banking closure without a remediation plan produces a cycle of declined applications. The risk at this stage is allowing operational pressure – the need to restore fiat rails quickly – to drive the decision toward an unregulated or poorly supervised payment provider, which creates further regulatory exposure.
Each profile requires a different sequence of legal and structural steps. We map that sequence in a scoped initial engagement before committing to a full programme of work.
A Common Assumption: One Licence Is Enough
A common assumption among operators approaching the banking market for the first time is that holding a single regulatory licence – particularly one obtained in a jurisdiction with a well-known name – resolves the correspondent banking question. It does not.
A licence addresses whether an activity is lawful in a given jurisdiction. Correspondent banking access addresses whether the entity holding that licence meets the risk management standards of a specific financial institution. Those are different assessments conducted by different functions within the bank, against different criteria. A VASP registration, a CASP authorisation or a payment institution licence demonstrates regulatory legitimacy; it does not demonstrate that the entity's AML programme, corporate structure or client profile meets the correspondent bank's own internal risk appetite.
In our experience, operators who approach banks with the assumption that their licence will do the commercial work for them consistently find that the bank's compliance team identifies additional requirements that the licence alone does not address. The effective position is to treat the licence and the banking relationship as two separate compliance exercises – each requiring specific preparation – that must be designed to work together from the outset.
The jurisdictional angle compounds this point. A firm licensed in one EU member state serving clients across the EEA under MiCA passporting is a very different correspondent banking proposition from a firm licensed in the same jurisdiction serving clients in multiple non-EU markets. The licence is the same; the banking risk profile is materially different. Correspondent banks assess the geographical scope of the business, not just the licence.
Related at OBOLUS
- Banking, Payments and EMI Onboarding – full practice overview covering fiat infrastructure, EMI licensing and payment structures for digital-asset firms
- Corporate bank account opening in Malta – jurisdiction-specific guidance on banking for MFSA-licensed and MiCA-authorised entities in Malta
- Staking and rewards taxation in Gibraltar – tax treatment of staking and on-chain reward income for businesses structured through Gibraltar
FAQ
Why do banks close crypto company accounts?
Banks close digital-asset company accounts primarily because the entity's risk profile, as assessed at a periodic compliance review, no longer satisfies the bank's internal risk appetite or correspondent banking policy. The most common proximate causes are an AML programme that has not kept pace with business growth, a change in the entity's activity or client profile that was not disclosed to the bank, or a broader de-risking decision applied to the digital-asset sector as a whole. Structural and documentation remediation is generally required before a new banking approach will succeed.
How can a VASP onboard with an EMI?
A VASP seeking to onboard with an EMI should prepare a documented compliance submission covering its regulatory status, UBO structure, AML and KYC policies, and the nature of its client base and transaction flows. The EMI's own compliance team will conduct enhanced due diligence on the VASP as a high-risk financial institution client. The VASP should also review the EMI's safeguarding model to ensure that client fiat funds held through the EMI are properly segregated and protected in the event of the EMI's insolvency – a requirement that typically flows from the VASP's own licence obligations.
What does client-money safeguarding require?
Client-money safeguarding requires a licensed operator to hold client fiat funds separately from its own operating capital, in a designated account at a regulated credit institution or in qualifying liquid assets. The obligation applies to EMIs under e-money and payment services regulation and to licensed VASPs and CASPs where their licence requires fiat segregation. The practical effect is that client funds must be ring-fenced and identifiable as such in the event of the operator's insolvency, protecting clients against the operator's own creditors.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the banking, payment and compliance structures that connect them. We map the licence stack across operating, custody and payment layers before you commit – because digital assets are the entirety of our practice. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory and Compliance Analyst – specialising in VASP and CASP licensing strategy, AML compliance architecture and correspondent banking access for digital-asset businesses across the EU, Gulf and Asia-Pacific hubs.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.