For institutional digital-asset businesses, losing a banking relationship is not a compliance inconvenience – it is an operational crisis. When a bank or electronic money institution (EMI) de-risks a crypto counterparty, fiat rails disappear overnight. Client settlements stall. Payroll and vendor payments miss deadlines. In the worst cases, the account closure triggers a cascade: other banking partners notice the exit, and the business finds itself locked out across multiple jurisdictions simultaneously. The legal question at that moment is not abstract. It is whether a challenge is possible, how fast it must move, and what structural changes would prevent the same outcome from repeating.
De-risking – the practice by which regulated financial institutions exit entire customer categories they perceive as high-risk – sits at the centre of the current digital-asset banking environment. Under anti-money-laundering regimes endorsed by the Financial Action Task Force (FATF), banks and EMIs are required to assess the risk presented by each customer. When that assessment produces a result the institution cannot manage within its own compliance budget, it exits. The exit is almost always lawful on the bank's side. Defence, therefore, is not about proving the bank acted illegally. It is about demonstrating, through structured legal and compliance argumentation, that the risk has been mis-assessed – and about engineering a licensing and banking architecture that prevents the next exit before it happens.
This page covers the regulated basis for de-risking, the anatomy of an effective defence, the cross-border considerations that determine whether a challenge will succeed, and the structural safeguards that reduce future exposure. We also address EMI onboarding as an alternative fiat-rails strategy for virtual asset service providers (VASPs) and other digital-asset operators.
Why De-risking Happens: The Regulatory Logic
De-risking is a rational response to asymmetric compliance cost, not a deliberate policy to exclude digital-asset businesses. A bank operating under AML/CFT obligations enforced by a domestic regulator faces a binary calculation: if the cost of monitoring a VASP customer – transaction surveillance, enhanced due diligence, correspondent-bank pressure – exceeds the revenue generated by that relationship, the bank exits. The exit is rarely targeted at any individual operator. It is a category decision.
The FATF framework, specifically its guidance on virtual assets and Recommendation 15, requires that financial institutions treat VASPs as a class requiring enhanced due diligence. That baseline requirement interacts with correspondent-bank pressure from institutions in New York, Frankfurt or London, which in turn constrains what local banks in smaller jurisdictions can offer to crypto-sector clients. The result is a structural squeeze: the more compliance pressure at the top of the correspondent chain, the narrower the banking options at the operating level.
A second pressure comes from the Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer). Banks that cannot confirm their VASP counterparty is compliant with the Travel Rule in every jurisdiction where it operates will often treat the entire relationship as unmanageable. An operator whose Travel Rule infrastructure is incomplete – or whose compliance documentation does not demonstrate completeness – is therefore a candidate for de-risking even if its underlying business is entirely legitimate.
In our practice, the most common precipitating event is not a regulatory finding against the operator. It is a change in the bank's own risk appetite, a new instruction from its compliance committee, or a correspondent bank restriction passed down without explanation. The operator learns about it through a notice period that may be short, and the formal reasons given are rarely the full picture.
What Does an Account Closure Notice Actually Trigger?
An account closure notice from a bank or EMI triggers a defined set of legal options and a tight factual window in which to exercise them. The first question is whether the notice period – typically set by the account agreement and local banking law – has been honoured. Where it has not, there may be a contractual remedy independent of any regulatory challenge.
The second question is whether the closure was accompanied by a suspicious activity report (SAR) referral or a law-enforcement hold. If it was, the account is not merely closed – it is restrained. The legal response to a SAR-related hold is materially different from a response to a pure commercial de-risking decision, and conflating the two wastes critical time.
The third question concerns the jurisdiction of the bank or EMI and the regulatory regime it operates under. A UK-authorised EMI operating under FCA supervision has different obligations toward its customers than an EMI authorised in an EU member state and operating under MiCA's transitional provisions. Similarly, a correspondent bank in a NYDFS-supervised group operates under different constraints than a regional bank in a jurisdiction with lighter AML enforcement. Each of those differences changes both the available challenge mechanisms and the likely response of the institution to a well-structured representation.
A formal representation – a legal letter setting out the compliance posture of the operator, the inadequacy of the bank's risk assessment, and the legal consequences of a precipitate closure – is often the most effective immediate intervention. In our experience, institutions that receive a structured legal response within the first several business days of issuing a closure notice will frequently extend the notice period to allow for a review. That extension buys the time needed either to resolve the issue or to transition to a replacement banking relationship with minimum operational disruption.
The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. To understand how this applies to your specific situation, contact OBOLUS at info@oboluslaw.com or map your options here.
The Cross-border Dimension: Where the Entity Sits vs. Where Banking Lives
The cross-border reality of digital-asset banking is that an operator's legal seat, its banking relationships and its user base almost never occupy the same jurisdiction. A VASP licensed under the VARA regime in Dubai may bank through an EMI regulated by the FCA in the UK, serve users across the EU under MiCA passporting, and hold custody assets through a Cayman-domiciled structure. Each of those links is a potential closure point.
De-risking in this environment is rarely a single-jurisdiction event. When a primary banking relationship collapses, the first response of an operator is often to approach an EMI in a different jurisdiction – only to discover that the EMI's own correspondent bank operates the same category exclusions as the bank that just exited. The result is a sequence of rejections that can appear, incorrectly, to confirm that the operator is unbankable.
The correct analysis starts one level up: at the correspondent-banking layer and the regulatory regime of the operator's licensed entity. An operator with a CASP authorisation under MiCA – the EU-wide crypto-asset service provider licence issued by a national competent authority and passportable across the EU/EEA – presents a categorically different compliance profile to a correspondent bank than an operator with a legacy offshore registration. Similarly, a VASP registered under the ADGM/FSRA regime in Abu Dhabi carries a regulatory imprimatur that EMIs and payment institutions in multiple jurisdictions recognise as a credible compliance signal.
The cross-border dimension also raises a forum question. If an operator's account is frozen rather than closed – whether by court order, regulatory action or a unilateral hold by the bank – the available legal response depends on which court has jurisdiction over the institution holding the account. England and Wales, the DIFC Courts in Dubai and Singapore are the leading forums for urgent injunctive relief in the digital-asset context, and operators whose structures connect to those jurisdictions retain materially broader options than those operating through less-recognised forums.
We regularly advise operators on structuring their banking and entity architecture before a crisis, precisely so that the jurisdictional options are preserved. A structure built without this in mind is a structure that closes options at the worst possible moment.
EMI Onboarding as a Strategic Alternative
For VASPs and other digital-asset operators who face persistent difficulty banking through traditional credit institutions, EMI onboarding – establishing a working relationship with a regulated electronic money institution – is increasingly the operational answer for accessing fiat rails. An EMI authorised in the UK under the FCA's Electronic Money Regulations or in an EU member state under MiCA's payment and e-money provisions can issue IBANs, hold funds on behalf of clients and execute payment orders, often with a higher tolerance for VASP counterparties than a full bank.
The onboarding process with an EMI, however, is not a lighter version of bank onboarding. EMIs are subject to the same FATF-derived AML/CFT obligations as banks, and their compliance teams will assess a VASP applicant's governance, its AML programme, its Travel Rule infrastructure and the jurisdictions in which it operates. An application that does not anticipate those questions – or that presents incomplete documentation of the operator's licensing status – will fail at the initial screening stage.
The key preparation steps for a successful EMI onboarding are the following. The operator must demonstrate a coherent licensing map: which jurisdictions it serves, under which regulatory permissions and how the permissions interact. It must show a documented AML/CFT programme – policies, risk methodology, screening processes and the responsible compliance officer. It must be able to describe its Travel Rule solution by name and explain how it handles data requirements at each transfer threshold. And it must provide a corporate-structure diagram that is clean, current and consistent with the information held by every other regulated counterparty.
In practice, the gap between a VASP that successfully onboards with an EMI and one that does not is almost never the underlying business risk. It is documentation quality and the clarity of the compliance narrative presented to the EMI's onboarding team. We have seen operators with strong underlying risk profiles rejected three or four times before engaging structured legal preparation – and then onboarded on the first properly prepared application.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital-Asset Businesses – the full practice overview covering licensing, fiat-rail access and account strategy across 70+ jurisdictions.
- PSP and Acquiring Agreement in Canada – structuring payment and acquiring access for digital-asset businesses operating in or through Canada.
- ADGM vs Switzerland: Where to License a Crypto Business – a comparative analysis of two leading licensing hubs and their banking environment implications.
What Operators Get Wrong: The Four Structural Mistakes
Most de-risking events that reach us as crisis instructions were foreseeable – and preventable. The pattern of errors is consistent enough across jurisdictions and operator types that it is worth stating directly.
The first and most common mistake is single-jurisdiction banking concentration. An operator that holds all of its fiat rails through one bank or one EMI has no operational redundancy. When that relationship closes, the business stops. The standard advisory position – which we build into every banking structure we review – is that operational, client-money and treasury functions should sit with different institutions where possible, and that at least one relationship should be in a jurisdiction with a strong legal regime for urgent account relief.
The second mistake is treating compliance documentation as a one-time exercise. Banks and EMIs review their customer risk assessments on a rolling basis. An operator that provided a clean compliance pack at onboarding but has since expanded its product range, added new jurisdictions or changed its corporate structure without notifying its banking partners will find that the periodic review produces a different result. Proactive disclosure of material changes – before the bank discovers them through transaction monitoring – is the single most effective retention tool available.
The third mistake is the belief that a single offshore registration is sufficient to satisfy all banking counterparties globally. This is the most persistent myth in the sector. An EMI onboarding team in London, Frankfurt or Singapore will assess the licensing status of a VASP applicant against the regulatory standard of the jurisdiction from which the operator actually serves clients – not the jurisdiction where the entity is registered. If the gap between those two is large, the application fails. The licence stack must match the operational footprint.
The fourth mistake is delay. The notice period in an account closure letter is a legal deadline, not a conversation opener. Operators who spend the first week of a notice period seeking informal reassurances from their relationship manager – rather than engaging legal counsel – regularly find that the formal window for a challenge or a structured transition has closed before they act.
Decision Matrix: Matching the Response to the Operator Profile
The appropriate response to a de-risking event depends on the operator's profile, the nature of the closure and the jurisdictional position of the relevant institution. The following analysis maps the most common configurations.
Profile A – Licensed VASP with a documented AML programme, closure on commercial grounds: The immediate response is a structured legal representation challenging the adequacy of the bank's risk assessment, citing the operator's licensing status and compliance infrastructure. The objective is an extended notice period and either a reversal or an orderly transition. Parallel EMI onboarding begins from day one of the notice period. Indicative process: structured representation within the first several business days; EMI applications running concurrently; decision typically within weeks rather than months.
Profile B – Operator with an incomplete licensing stack, closure combined with a transaction monitoring flag: The immediate response separates the legal and compliance workstreams. Counsel assesses whether the closure is purely commercial or whether there is a regulatory dimension. If there is a SAR or law-enforcement element, the account-closure defence is secondary to understanding and responding to that. The licensing gap is addressed in parallel – but it must be addressed, because no EMI will onboard an operator whose licensing position is unclear. Timeline: longer, determined by the complexity of the regulatory position.
Profile C – Established operator in multiple jurisdictions, closure by one banking partner in a secondary market: The operational impact is contained. The legal response focuses on a formal representation and, where the banking relationship has material commercial value, a potential complaint to the relevant financial ombudsman or regulator. The structural lesson – adding a redundant banking relationship in that jurisdiction before the crisis, not after – is built into the post-resolution architecture review. This is the profile where pre-emptive structuring delivers the clearest return on investment.
If a recovery clock is running or a closure notice has already been issued, reach our disputes and banking desk now at info@oboluslaw.com or map your options.
Client-Money Safeguarding and Payment Licence Interaction
De-risking does not only affect the operator's own operating account. For VASPs and payment institutions that hold client money, a closure notice creates an immediate question about the safeguarding of those funds. Under most regulated payment and e-money regimes – including the applicable provisions under MiCA and the FCA's payment services rules – client funds must be kept in a segregated account at a credit institution or invested in qualifying liquid assets. If the institution holding those segregated funds closes the account, the operator faces a legal obligation to replace the safeguarding arrangement immediately.
Failure to maintain compliant safeguarding is not a technical breach. It is a reportable event under most payment licence conditions and, if it persists, a ground for licence suspension or revocation. The legal response to a de-risking event that affects safeguarding accounts must therefore run faster than the response to a closure of an operating account. The regulator may need to be notified within a defined period, and the replacement safeguarding arrangement must be operational before the existing one closes.
This intersection of banking and payment licence risk is one of the least-discussed consequences of de-risking in the institutional context. In our practice, we treat it as a standalone workstream within any de-risking instruction – separate from the challenge to the closure itself and from the EMI onboarding process – because the regulatory consequences of getting it wrong run independently of whether the challenge to the original closure ultimately succeeds.
A micro-matter from our recent work illustrates the point. A licensed payment institution – operating across several EU member states under passporting – received a closure notice from its primary EMI in the first quarter of a recent year. The operator's client funds were held entirely within the same institution. We identified the safeguarding exposure within hours of receiving the instruction, filed a precautionary notification with the relevant national competent authority, and began parallel applications with two alternative safeguarding-compliant institutions. The closure notice period was used in full for the formal legal representation; the client-money replacement was operational before the original account closed. No licence breach was recorded.
A Common Assumption: If the Bank is Acting Lawfully, There is Nothing to Do
A common assumption among operators facing de-risking is that because the bank has a legal right to exit the relationship, there is no legal avenue available. That assumption is usually wrong in two distinct ways.
First, the bank's right to close an account is not unconditional. It operates within the terms of the account agreement, the notice obligations set by applicable banking law and, in some jurisdictions, supervisory guidance that constrains how financial institutions may treat certain categories of customer. An institution that closes an account without adequate notice, without complying with its own stated process or without giving the customer a genuine opportunity to address the identified concern may be in breach of those obligations even if the decision to de-risk is itself legitimate.
Second, even where the closure is legally unimpeachable on the bank's side, the legal response has commercial value. A well-constructed representation – delivered through counsel, citing the operator's regulatory status and compliance posture – changes the tone of the relationship. Institutions responding to a formal legal letter engage differently than institutions responding to a relationship manager's inquiry. In our experience, a significant proportion of closure decisions that appear final at the point of notice are reversed, deferred or converted to an enhanced-monitoring arrangement when the operator presents a properly structured legal response.
The myth that a single offshore licence resolves the banking problem is the corollary error. An EMI onboarding team assesses the legal reality of where a business operates and who it serves – not the legal fiction of where its registration lives. Operators that have structured their licensing to match their actual operational footprint, and that can demonstrate that match to a banking counterparty, are materially better positioned in both the initial onboarding process and any subsequent de-risking defence.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, payment institutions and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the banking, tax and compliance structures that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and when a banking crisis is live, our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums. To discuss your situation, contact info@oboluslaw.com or reach us via t.me/oboluslaw.
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because the compliance cost of monitoring a VASP relationship – enhanced due diligence, transaction surveillance, correspondent-bank pressure – exceeds the commercial return. FATF Recommendation 15 requires institutions to treat VASPs as a higher-risk category. When a bank's internal risk appetite changes, or its correspondent bank restricts the category, individual operators exit regardless of their own compliance quality. A documented AML programme and a clear licensing map are the most effective retention tools available to the operator.
How can a VASP onboard with an EMI?
A VASP seeking to onboard with a regulated EMI must present a coherent licensing map showing the jurisdictions it serves and the regulatory permissions it holds, a documented AML/CFT programme with a named compliance officer, a specific Travel Rule solution covering all relevant transfer thresholds, and a clean current corporate-structure diagram. The EMI's onboarding team will assess these against its own risk criteria. Incomplete documentation is the primary reason for rejection – not the nature of the underlying VASP business. Structured preparation before the application materially improves success rates.
What does client-money safeguarding require?
Under most regulated payment and e-money regimes – including MiCA and applicable FCA rules – client money must be held in a segregated account at a credit institution or invested in qualifying liquid assets, separately from the operator's own funds. If the institution holding the safeguarding account closes it, the operator must replace the arrangement before the account closes and may be required to notify the relevant regulator within a defined period. Failure to maintain compliant safeguarding is a reportable licence condition breach, independent of any challenge to the underlying account closure.
By Victor Olsen, Regulatory and Compliance Analyst – specialising in digital-asset regulatory structuring, de-risking defence and AML/CFT compliance frameworks for institutional crypto operators across the EU, UK and UAE regimes.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.