Correspondent banking access is the single most common operational crisis we see in digital-asset practices today. A licensed VASP (virtual asset service provider) secures its regulatory authorisation, builds its compliance programme and then discovers that every candidate bank treats the account application as a material risk event — requiring enhanced due diligence, months of review and, frequently, a flat refusal. The fiat rails the business depends on are simply not there. This page sets out the regulated basis for that scrutiny, the process by which banks and EMIs (electronic money institutions) assess crypto counterparties, the structural mistakes that cause rejections, and the cross-border reality that most operators underestimate.
Why Banks Treat Crypto Counterparties as Heightened Risk
Correspondent banking access under heightened scrutiny arises because global AML/CFT (anti-money laundering and countering the financing of terrorism) standards, anchored in the FATF Recommendations and specifically FATF Recommendation 15 on virtual assets, impose an obligation on financial institutions to assess and manage the risks posed by virtual-asset exposure. A bank that maintains a correspondent relationship with a crypto-native business inherits a slice of that business's risk profile. Regulators in major financial centres — the FCA in the UK, the Federal Reserve and FinCEN in the United States, the MAS in Singapore, ESMA and national competent authorities in the EU — have all issued guidance indicating that VASPs represent a category requiring elevated scrutiny at onboarding and on an ongoing basis.
The consequence is structural, not merely procedural. Banks do not simply apply a longer checklist. They conduct a full risk-appetite determination: whether digital-asset clients fall within their permitted risk categories at all, and if so, whether the specific client's profile — its licence jurisdiction, its customer base, its transaction volumes, its blockchain exposure — sits within acceptable parameters. Many institutions have concluded that the cost of managing VASP relationships, in compliance resource and regulatory capital, exceeds the fee income. That is the architecture of derisking.
For a payments company or exchange seeking fiat rails across more than one currency corridor, the problem compounds: each correspondent in the chain applies its own risk-appetite rules. A US correspondent bank reviewing a cross-border payment chain that touches a VASP — even indirectly — may apply NYDFS guidance alongside FinCEN expectations. The operating company in, say, the UAE under VARA regulation may be fully licensed; the US correspondent may still require its own due-diligence pack.
In our practice, we advise operators at every stage of this process. We have seen businesses lose established banking relationships at 24 hours' notice when a correspondent's internal policy changed. We have also seen well-structured operators — with the right licence, the right documentation and the right legal framing — onboard at institutions that others considered inaccessible.
The process above describes the standard path. Your facts — the entity structure, the user base, the currency corridors and the banking jurisdiction — change the analysis materially. For a scoped assessment of your correspondent banking position, contact OBOLUS at info@oboluslaw.com.
What Banks Actually Review During Enhanced Due Diligence
Enhanced due diligence for a VASP correspondent-banking application covers six substantive areas, each of which maps to a specific regulatory expectation that the bank must evidence to its own supervisors.
The first is licensing status. The bank verifies not merely that a licence exists, but which activities it covers, which jurisdiction issued it, and whether that jurisdiction's AML/CFT supervision is considered adequate. A registration under the BVI VASP Act 2022 is treated differently from a full CASP authorisation (crypto-asset service provider authorisation) under MiCA issued by a recognised EU national competent authority. The bank's correspondent-banking team will assess whether the issuing regulator is a FATF member, whether it conducts supervisory examinations, and whether the licence is activity-specific or generic.
The second is the compliance framework. Banks want to see a documented AML/CFT programme that is proportionate to the operator's risk profile. That means a written risk assessment, a transaction-monitoring policy, and evidence of the Travel Rule (the obligation to pass originator and beneficiary data with virtual-asset transfers) implementation — or a credible roadmap to compliance where the Travel Rule threshold has not yet been triggered.
Third, the bank reviews the customer base. A VASP serving institutional clients exclusively is a categorically different risk profile from one serving retail customers in jurisdictions with weak financial-system integrity. The bank will ask for a customer risk-rating methodology and representative data on the client book.
Fourth, transaction-monitoring and blockchain analytics (the use of on-chain forensic tools to identify high-risk wallet addresses and counterparty exposure) is now an expected capability. Banks increasingly ask which analytics provider a VASP uses. Operators who cannot name a credible on-chain monitoring tool — or who have no policy on handling alerts — fail at this point.
Fifth, the bank considers the jurisdiction of operations versus the jurisdiction of incorporation versus the jurisdiction of users. A company incorporated in the Cayman Islands under CIMA supervision, operating commercially through a VARA-licensed Dubai entity, serving European users under MiCA's reach — each layer raises a question. The bank must be satisfied that the entity it is banking is the correct legal entity and that no regulatory arbitrage is occurring.
Sixth, beneficial ownership. The FATF Recommendations require financial institutions to identify and verify the ultimate beneficial owner of any legal person before establishing a business relationship. For digital-asset businesses with layered holding structures — which is common — this requires a complete ownership chart supported by corporate documents.
What Are the Most Common Structural Mistakes That Block Access?
The single most frequent cause of a rejected correspondent-banking application is a mismatch between the regulatory perimeter of the licence and the actual activities the business conducts. A licence that covers exchange services does not automatically cover custody or lending. A bank that identifies unlicensed activity in the application pack — or discovers it during ongoing monitoring — will exit the relationship. We have seen this repeatedly.
The second common mistake is presenting a compliance programme that is conceptually sound but not evidenced. A policy document alone is insufficient. Banks want to see records of implementation: training logs, SAR filing history (described as a process, not the documents themselves), screening records, transaction-monitoring alert resolution. A compliance programme that exists only in a policy manual is, from the bank's perspective, no programme at all.
The third mistake is mischaracterising the licence jurisdiction. Operators sometimes present a registration in a jurisdiction with limited supervisory capacity as equivalent to a full authorisation in a flagship hub. Banks with experienced VASP teams are familiar with the difference between a FINMA-supervised entity in Switzerland and a light-touch registration elsewhere. Misrepresenting the strength of the licence is not merely counterproductive — it raises integrity concerns that will end the relationship permanently.
The fourth, and increasingly significant, mistake is an incomplete Travel Rule posture. Under MiCA, under the Singapore Payment Services Act, and under UK FCA guidance, VASPs are expected to implement the Travel Rule. A business that cannot demonstrate either current compliance or a time-bound implementation plan will face difficulty with any bank that is itself supervised in a Travel Rule-implementing jurisdiction.
A common assumption we hear from operators is that a single offshore licence is sufficient to serve clients globally without further regulatory engagement. It is not. Banks assess the regulatory substance of the licence, not its existence. A registration that imposes no ongoing supervisory examination, no capital requirement and no AML audit expectation will be treated with correspondingly less weight — regardless of which flag it carries.
How Does the Cross-Border Structure Affect the Banking Analysis?
For a digital-asset business operating across multiple jurisdictions — which describes virtually every serious exchange, custodian or payment operator — the correspondent-banking question is never answered at a single entity level. Each legal entity in the group requires its own banking relationship, and each relationship is assessed by reference to the entity's own licence, its own activity and its own user base.
Consider a typical operator structure: a holding company domiciled in the Cayman Islands; an operating company in Dubai holding a VARA licence; a separate EMI licence-holder in an EU jurisdiction for euro-denominated payment services. The Dubai entity needs AED and USD banking. The EU EMI needs a euro correspondent and potentially a SEPA settlement account. The Cayman holding company needs a bank that is comfortable with a digital-asset investment holding structure. Three separate banking relationships, three separate enhanced due-diligence processes, potentially three different regulatory regimes being assessed by three different institutions.
In our cross-border practice, we regularly advise on sequencing this build — which entity to bank first, which relationships create the most leverage and credibility for subsequent applications, and how to present the group structure consistently across all applications. Inconsistency between how the group is described to one bank versus another is a significant red flag in ongoing monitoring and a common cause of exits.
The EU dimension adds a further layer. Under MiCA, CASP-authorised entities may passport across EU member states. But a passported CASP still needs a banking relationship in each currency it handles. The MiCA passport does not confer a right to a bank account — it confers the right to provide services. The banking question remains entirely commercial, governed by each institution's own risk appetite and supervised by its own regulator.
EMI onboarding follows a parallel track. An EMI authorised under the EU's Payment Services Directive, or a registered EMI in the UK under FCA oversight, can provide payment accounts that function as near-substitutes for bank accounts in certain operational contexts. However, EMIs themselves face scrutiny from their own correspondent banks and are often reluctant to onboard VASPs without the same documentation package described above — frequently supplemented by their own specific questionnaire covering on-chain exposure and blockchain analytics.
Decision Matrix: Which Structure Fits Which Operator Profile?
The right banking and payment architecture depends on the operator's activity, user base and existing licence stack. The following profiles reflect the patterns we see most frequently in practice.
Profile A: VASP with a single MiCA CASP authorisation, EU users, primarily euro flows. This operator's strongest path is to establish a primary banking relationship with a euro-area institution that has a published or demonstrable appetite for MiCA-authorised counterparties. Supplementing with an EMI relationship for payment account services is common. Timeline to onboarding is typically measured in weeks, assuming a complete compliance documentation pack, a credible blockchain analytics tool and no adverse transaction history. Key risk: the MiCA passport does not insulate against individual bank exits if the operator's transaction volume or customer-risk profile changes materially.
Profile B: VARA-licensed exchange in Dubai, serving non-EU users, USD and AED primary currencies. The VARA framework is well-recognised among regional banks and a growing number of international institutions with Gulf operations. However, USD correspondent access — which routes through US-regulated banks — remains more difficult. Any US correspondent will apply FinCEN guidance and potentially NYDFS standards by analogy, regardless of where the operator is licensed. This operator should expect a longer enhanced due-diligence process for USD rails, may need to engage allied counsel in the relevant jurisdiction for the US banking dimension, and should have a documented policy on US-person exclusion if it does not hold federal or state US licensing. Key risk: US correspondent exits driven by policy changes that have nothing to do with the operator's own compliance quality.
Profile C: Custodian licensed under ADGM's FSRA regime, serving institutional clients, multi-currency. Institutional-client VASPs face a somewhat more accommodating banking environment than retail-facing operators, because the customer-base risk profile is lower and the transaction volumes are typically more predictable. The FSRA's regulatory standing is well-regarded by international banks with ADGM presence. The key documentation requirement at this level is a demonstrated ability to segregate client assets, a robust custody policy aligned with the FSRA's expectations, and evidence of institutional-grade blockchain analytics and counterparty-screening. Key risk: over-reliance on a single institution; diversification across at least two banking relationships is strongly advisable at this scale.
Correspondent Banking Restored for a Licensed Payments Operator
In a recent matter, a payment institution holding an EU electronic money licence found itself debanked by its primary correspondent following a portfolio-wide risk review that the bank conducted across its VASP clients. The operator had no adverse transaction history and a fully documented compliance programme. The exit was driven entirely by the bank's revised internal risk-appetite policy. We were instructed to structure a remediation approach: we prepared a comprehensive correspondent-banking memorandum — mapping the operator's licence scope, its Travel Rule implementation status, its blockchain analytics coverage and its customer risk-rating methodology — and identified three candidate institutions whose published regulatory strategies indicated an appetite for licensed EMI-VASP counterparties in this size range. Within approximately two months, the operator had received a formal onboarding offer from one institution and was in advanced due diligence with a second. Fiat operations resumed before the end of the quarter.
How Do You Build a Documentation Pack That Survives Bank Scrutiny?
A defensible banking application for a digital-asset business is not simply a KYC submission — it is a legal-and-compliance narrative that pre-empts the specific questions an experienced VASP banking team will ask. The structure we use with operators we advise follows a consistent architecture.
The opening section is a corporate and regulatory summary: the entity hierarchy, every licence held (with the issuing authority, the date of authorisation and the covered activities named precisely), and the regulatory status in each jurisdiction where the business operates commercially. This section must be internally consistent — any discrepancy between the group structure as described in the application and what is discoverable from public registers is an integrity red flag.
The second section is the AML/CFT programme summary. This is not the programme itself — banks do not read 200-page policies during initial onboarding — but a structured executive summary, typically 8 to 12 pages, covering risk assessment methodology, customer due-diligence procedures, transaction monitoring, the Travel Rule implementation status and the escalation and reporting framework.
Third: the blockchain analytics section. This should name the tool or tools used, the transaction-monitoring alert thresholds and the investigation workflow. Where the operator has taken a risk decision to continue a relationship despite a medium-risk wallet-screening flag — which is a legitimate and documented decision — that decision process should be described generically to demonstrate a functioning governance process.
Fourth: beneficial ownership documentation. A clean, current ownership chart, supported by the appropriate corporate registry filings, notarised where required by the banking jurisdiction's KYC standards. For structures involving trusts or nominees, additional documentation confirming the underlying beneficial interest is required. This section should be prepared to the standard of a court exhibit — because in a subsequent dispute about the relationship, that is exactly what it may become.
Fifth: a forward-looking section addressing growth plans, anticipated changes in product scope or geography, and how those changes will be managed from a compliance and licensing perspective. Banks are not only assessing today's risk — they are making a credit and compliance commitment that they will have to defend to their own supervisors in future examinations. An operator that can demonstrate awareness of its own forward risk profile is a materially more credible counterparty.
If a prior application stalled or a banking relationship was closed without clear explanation, a structural review of the documentation pack can surface the specific reason and the path to remediation. Write to us at info@oboluslaw.com to request a scoped assessment.
Self-Assessment: Is Your Banking Position Defensible?
Before approaching a correspondent institution — or responding to a request for information from an existing bank — an operator should be able to answer affirmatively to the following questions. These are not our checklist; they reflect the standard due-diligence frameworks applied by compliance teams at institutions with developed VASP policies.
Does every activity you conduct commercially fall within the scope of a current, active licence issued by a recognised regulatory authority? If any activity sits outside the licence perimeter, the gap must be closed — either by extending the licence or by ceasing the activity — before a banking application is made.
Is your Travel Rule implementation either live or subject to a documented, time-bound remediation plan? Banks operating in Travel Rule-implementing jurisdictions are expected by their own supervisors to assess whether their VASP counterparties are compliant. An operator that cannot answer this question will face difficulty even where its other compliance elements are strong.
Can you produce, within 48 hours, a complete beneficial ownership chart and supporting corporate documentation? In an ongoing relationship, a bank may request an updated ownership confirmation at any time. The inability to respond promptly is itself treated as a risk indicator.
Is your blockchain analytics coverage proportionate to your transaction volumes and counterparty base? A spot-check tool used occasionally is not the same as a systematic transaction-monitoring programme with documented alert thresholds and investigation records.
Is the entity you are banking the correct legal entity — the one that actually holds the licence, has the users and generates the revenue? Banking the holding company while the regulated entity conducts business elsewhere is a structure that will not survive enhanced due diligence.
Related at OBOLUS
- Banking, Payments & EMI Onboarding for Digital-Asset Businesses – the full practice overview covering licensing, payment accounts and fiat-rail architecture across 70+ jurisdictions
- EMI Onboarding for VASPs Under Heightened Scrutiny – how to structure and present an EMI account application for a VASP counterparty
- Digital Asset Custody Authorisation in ADGM – the FSRA licensing process for custodians in Abu Dhabi Global Market
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because VASPs are classified as heightened-risk counterparties under AML/CFT frameworks anchored in the FATF Recommendations. Specific triggers include a change in the bank's internal risk-appetite policy, identification of unlicensed activity, inadequate Travel Rule compliance, undisclosed changes in the operator's customer base or transaction profile, and portfolio-wide derisking exercises unrelated to the individual operator's conduct. In our practice, the majority of exits we see are policy-driven rather than conduct-driven — but the remediation path is the same in either case.
How can a VASP onboard with an EMI?
A VASP seeking an EMI account should approach the process as a full enhanced due-diligence application, not a standard business account opening. The EMI will require a complete licence and corporate documentation pack, an AML/CFT programme summary, evidence of Travel Rule implementation or a remediation plan, and blockchain analytics coverage documentation. EMIs authorised under the EU Payment Services Directive or FCA-registered in the UK are themselves supervised entities; they face regulatory scrutiny for their VASP clients and will apply risk-appetite standards accordingly. Preparation of a structured banking memorandum significantly improves onboarding outcomes.
What does client-money safeguarding require?
Client-money safeguarding, as required of EMIs under the EU Payment Services Directive and UK FCA rules, obliges the institution to hold funds received from payment service users either in a segregated account at a credit institution or invested in secure liquid assets, kept separate from the institution's own funds. For a VASP relying on an EMI for payment services, the practical consequence is that client fiat balances are segregated from operational funds — a protection that is relevant both to counterparty-risk management and to the bank's own assessment of the EMI's risk profile.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, banking and payment stack — operating, custody and payment layers — before operators commit to a structure. To discuss your correspondent banking position, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst — specialising in VASP regulatory frameworks, AML/CFT programme design and correspondent banking documentation for digital-asset businesses across multiple jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.