A regulated crypto business can hold every required licence and still lose its fiat rails overnight. De-risking – the practice by which banks and EMIs (electronic money institutions) close or refuse accounts for entire business categories rather than individual customers – is the single most disruptive operational risk facing exchanges, custodians and payment firms today. With compliance regimes converging on the MiCA model and supervisors from the FCA to VARA tightening VASP oversight, the correspondent banking environment for digital-asset businesses has not simplified. It has stratified: institutions that can demonstrate clean governance and genuine regulatory standing retain access; those that cannot are de-banked at speed.
This page explains what account closure defence looks like in practice, how it intersects with the EMI onboarding process, and where cross-border structuring decisions change the outcome. Each section is written for the general counsel or CFO who needs the legal answer, not background reading.
What is de-risking and why does it fall on regulated entities?
De-risking is the decision by a bank or EMI to exit a customer relationship based on perceived category-level risk rather than individual assessed risk. Regulators including FATF and ESMA have recognised the phenomenon and criticised it as a distortion of proportionate risk management, yet it persists because the compliance cost of retaining a crypto client still exceeds the fee revenue at many institutions. For a licensed VASP or CASP (crypto-asset service provider under MiCA), the practical effect is the same whether the closure is labelled "de-risking" or "policy exit": fiat rails stop, settlement fails and the business is operationally stalled.
The problem concentrates on regulated entities in a specific way. An unlicensed operator simply lacks the paper trail to contest closure. A properly licensed firm – one holding, for example, a VARA licence in Dubai, a CASP authorisation in an EU member state, or registration under the BVI VASP Act 2022 – has a documented compliance record that can be deployed. The failure is almost always a communication failure: the bank's compliance function never received, or never evaluated, the full regulatory picture. That gap is where defence work begins.
FATF Recommendation 15 and its interpretive guidance establish that de-risking should not be the default response to VASP exposure; national supervisors are expected to convey this to their banking sectors. In practice, the supervisory signal has been uneven. Operators we advise in multiple jurisdictions report that banking relationships remain the hardest operational problem to solve, outpacing licence timelines and AML programme design.
How does the account closure defence process work?
Effective defence against account closure follows a defined sequence that begins before notice is served and ends, if necessary, before a supervisory authority or ombudsman. The process has four identifiable stages.
The first stage is pre-termination engagement. Most jurisdictions require a bank or EMI to provide notice before closing a business account – the notice period varies by jurisdiction and contract, but it is rarely more than a few weeks. That window is the primary opportunity. A formal response that presents the entity's regulatory status, transaction-monitoring programme, AML controls and the names of its supervisors – framed as a legal memorandum, not a complaint letter – changes the dynamic. We have seen institutions reverse pre-termination decisions at this stage when the compliance narrative was presented in a format their risk team could evaluate.
The second stage is formal objection and escalation. Where the institution maintains its decision, the regulated entity may escalate internally to the institution's compliance committee or board, and externally to the relevant supervisor. In the UK, the FCA's business account access powers and the broader supervisory expectations on banks create a channel for formal escalation. In the EU, MiCA-adjacent guidance and EBA positions on payment account access provide similar leverage. Neither route guarantees reinstatement, but both create a record and impose a response obligation on the institution.
The third stage is supervisory complaint. Regulators in leading jurisdictions have formal complaint mechanisms. Filing a supervisory complaint on behalf of a licensed entity serves two purposes: it triggers a response obligation and it creates documented evidence of the institution's conduct, which is relevant if litigation follows.
The fourth stage is legal proceedings. In jurisdictions with strong rule-of-law frameworks – England and Wales, Singapore, the DIFC Courts – a business can seek injunctive or declaratory relief where account closure causes demonstrable, imminent harm. This is not the default path; it is a last resort where other stages have failed and the commercial stakes justify it. In our cross-border practice, the threat of proceedings alone, properly constructed, is often sufficient to produce a managed exit or a transition period rather than immediate closure.
CTA #1 – The sequence above describes the standard path. Your facts – the entity's regulatory status, the jurisdiction of the institution, the governing contract law, and the banking relationship history – change the analysis materially.
If you have received a closure notice or expect one, contact OBOLUS at info@oboluslaw.com for a scoped assessment of your options.
Is EMI onboarding a viable alternative to bank accounts?
For many regulated crypto businesses, an EMI (electronic money institution) relationship is not a fallback – it is the structurally correct primary fiat rail. EMIs licensed under MiCA-adjacent regimes or national e-money frameworks can issue IBANs, process SEPA and SWIFT flows, and hold client money under regulatory safeguarding requirements. For a VASP or CASP operating in the EU or EEA, an EMI relationship with a MiCA-compliant counterparty offers a level of supervisory symmetry that a traditional bank rarely provides.
The onboarding process at an EMI is, however, substantively a compliance exercise. The EMI's AML function will conduct a business-risk assessment that mirrors the one a bank would perform. The differentiator is that a digitally native EMI typically has a compliance team that understands crypto transaction flows, sanctions screening at the blockchain level, and the significance of a CASP or VARA licence. The regulated entity's task is to present its programme in the terms that EMI compliance teams are trained to evaluate.
In our practice, the documents that determine EMI onboarding outcomes are: the AML/CFT policy and risk assessment, transaction-monitoring configuration evidence, the regulatory authorisation certificate and any supervisory correspondence, the ownership and control structure with UBO verification, and the operating model description covering on-chain and off-chain flows. An incomplete or generic AML policy is the single most common reason for EMI refusal at the first stage.
Cross-border note: an EU-licensed EMI can passport services across the EEA under MiCA's predecessor e-money frameworks and, progressively, under the MiCA regime itself. A VASP operating from the UAE under VARA, or from the BVI under the VASP Act 2022, will typically need to engage an EU EMI through a correspondent or intermediary arrangement rather than a direct authorised relationship. The structural design of that arrangement determines the regulatory exposure on both sides.
How does a cross-border structure affect fiat rail security?
For a business whose entity sits in one jurisdiction, whose users are in another, and whose banking must operate across both, de-risking risk is compounded at every structural layer. The most common pattern in our practice is a licensed operating entity in a recognised hub – ADGM, the AIFC, a MiCA jurisdiction – with payment flows running through an EU or UK EMI and end-user exposure across multiple regions. Each of those relationships carries its own closure risk, and a break at any point stalls the whole.
The legal question is how to design the structure so that no single bank or EMI exit is operationally catastrophic. The answer involves three elements. First, regulatory diversification: the operating entity should hold or be accessible to licences in more than one major hub where the user base justifies it. A VARA licence in Dubai and a CASP in an EU member state give the business two distinct regulatory identities to present to banking counterparties in different regions. Second, rail redundancy: primary and secondary EMI relationships at different institutions reduce single-point-of-failure risk. Third, contractual architecture: the terms governing each fiat-rail relationship should be reviewed for notice obligations, transition provisions and dispute escalation rights before the relationship begins, not after notice is served.
The Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer) adds a further dimension. Banks and EMIs increasingly require evidence that the VASP or CASP on the other side of a payment flow is Travel Rule compliant. A regulated entity that cannot demonstrate Travel Rule capability – a functioning policy, a technology solution, and documented counterparty screening – will face de-risking pressure regardless of its licence status. The FATF Travel Rule, now implemented in substance by MiCA and most leading regimes, is effectively a banking access requirement as much as an AML obligation.
What are the most common mistakes regulated entities make?
The mistakes that lead to account closure, and that undermine closure defence, are consistent across jurisdictions. Four recur with enough frequency to address directly.
The first is presenting a licence without the compliance narrative. A VARA authorisation certificate or a MiCA CASP approval is a regulatory fact, not a compliance argument. A bank or EMI compliance team needs to understand not just that the entity is licensed but what controls the licence entails: the transaction-monitoring regime, the AML officer's credentials, the suspicious-activity reporting process, the sanctions screening configuration. Regulated entities frequently submit the certificate and nothing else.
The second is assuming the licence resolves the risk categorisation. Banks apply their own internal risk models, which are not required to mirror the regulator's assessment. A CASP authorisation under MiCA does not prevent a bank from categorising crypto businesses as high-risk; it gives the entity grounds to demonstrate that its specific risk profile is manageable. The legal task is to translate the regulatory record into the bank's risk framework, not to assert that the framework should not apply.
The third is responding to a closure notice without legal counsel. The notice period is a statutory or contractual right, not a grace period. Every communication during that window is a formal record. A poorly worded response can limit later options.
The fourth is structuring with a single fiat rail and no contingency. This is not a legal mistake in isolation, but it becomes one the moment closure notice arrives, because the urgency removes negotiating leverage and legal options that would have been available with more time.
CTA #2 – If a prior banking relationship stalled or a closure notice has already been served, a second-opinion review can surface the structural reason and identify the available routes. Write to info@oboluslaw.com to request a scoped assessment.
Which approach fits which operator profile?
The right defence and banking strategy depends on the operator's specific profile. The following decision paths cover the most common configurations we encounter.
Profile A – EU-licensed CASP with a single EMI relationship receiving a closure notice: The primary instrument is a formal legal response during the notice period, presenting the CASP authorisation, the AML programme and the entity's supervisory record. If the EMI maintains its decision, escalation to the relevant national competent authority and, in parallel, identification of a secondary EMI with supervisory symmetry. Timeline: the notice period (typically weeks, not months) sets the outer bound; secondary EMI onboarding in parallel. Key risk: the AML programme is not documented in a form the EMI can evaluate – address first.
Profile B – VARA-licensed entity in Dubai seeking EU fiat rails: The instrument is structured EMI onboarding via an EU or EEA-licensed institution, supported by a cross-border compliance package that addresses VARA's regime requirements and translates them for an EU compliance audience. Allied counsel in the relevant EU jurisdiction support the EMI's internal review. Timeline: EMI onboarding timelines vary by institution; allow for a substantive compliance review period. Key risk: the VARA regime is not familiar to all EU EMI compliance teams – the narrative must bridge the gap explicitly.
Profile C – BVI or Cayman-registered fund or operator seeking correspondent EMI access: Offshore-registered entities face the highest de-risking pressure. The instrument is typically a combination of a regulated operating subsidiary in a recognised hub (ADGM, AIFC, a MiCA jurisdiction) and a correspondingly structured EMI application. The offshore entity alone is unlikely to sustain a direct EMI relationship in the EU or UK. Timeline: establishing the regulated subsidiary adds time but removes the structural vulnerability. Key risk: the operating substance of the hub subsidiary must be genuine – regulators and EMIs both examine it.
A common assumption to address directly
A common assumption among operators entering the market is that a single offshore licence provides a sufficient foundation for global operations, including banking access. In practice, the relationship between licence jurisdiction and banking access is indirect. A BVI VASP registration or a Cayman structure may be appropriate for certain fund vehicles or product types, but neither provides the supervisory standing that major banks and EMIs require to justify a direct relationship with a crypto business. The entities that maintain stable fiat access are those that hold licences in jurisdictions whose AML regimes are assessed as robust by the relevant banking-sector risk models – MiCA member states, MAS-licensed entities in Singapore, SFC-regulated platforms in Hong Kong, ADGM/FSRA-authorised firms in Abu Dhabi. The licence jurisdiction is a banking decision as much as a regulatory one.
Self-assessment checklist before approaching a bank or EMI
Before initiating or defending a banking relationship, a regulated entity should be able to confirm the following without hesitation. A gap in any item predicts a compliance objection.
- A current regulatory authorisation from a recognised supervisor, with no open enforcement actions.
- A written AML/CFT policy and risk assessment, updated within the current calendar year.
- A documented transaction-monitoring configuration with evidence of recent testing or audit.
- A Travel Rule policy and a deployed technology solution, with counterparty screening records.
- A clear ownership and control chart with UBO documentation verified to the applicable standard.
- A defined operating model description covering both on-chain flows and fiat conversion points.
- A designated AML compliance officer with documented responsibilities and relevant experience.
- At least one secondary fiat-rail option identified and in preliminary onboarding discussion.
In our cross-border practice, the entities that pass EMI and bank compliance review most quickly are those that treat this list as a living set of documents rather than a one-time filing exercise. Supervisors increasingly expect the same.
A recent matter in brief
In a recent matter, a payments firm holding a CASP authorisation in an EU member state received a sixty-day account closure notice from its primary EMI, citing a policy-level decision to exit the digital-asset sector. We prepared a formal legal response within the notice period presenting the entity's full compliance record – the CASP certificate, AML programme, transaction-monitoring reports and the relevant supervisory correspondence – framed as a compliance assessment rather than a complaint. The EMI's compliance committee reviewed the file and extended the relationship subject to enhanced monitoring. In parallel, we initiated structured onboarding with a secondary EMI as a contingency. The operator exited the situation with primary banking intact and a secondary rail in place. No litigation was required.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital-Asset Businesses – practice overview covering the full banking access and payments regime for crypto operators.
- Fiat On/Off-Ramp Banking for Regulated Entities – structured banking solutions for the fiat conversion layer of a digital-asset operation.
- Travel Rule Compliance Programme – Cross-Border Perspective – building a Travel Rule programme that satisfies both regulators and banking counterparties.
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because of category-level risk assessments rather than individual customer conduct. The compliance cost of maintaining adequate monitoring for a crypto business often exceeds the fee income it generates at many institutions. Additionally, correspondent banking pressure, sanctions screening complexity and, in some cases, regulatory uncertainty in the bank's home jurisdiction all contribute. A licensed entity with a well-documented AML programme and a recognisable regulatory standing is better positioned to defend against or prevent closure than an unlicensed or poorly documented operator, but the category risk remains a real factor that requires active management.
How can a VASP onboard with an EMI?
A VASP (virtual asset service provider) can onboard with an EMI by presenting a compliance package that the EMI's AML function can evaluate against its own risk framework. The core documents are the regulatory authorisation, the AML/CFT policy and risk assessment, evidence of transaction-monitoring configuration, a Travel Rule policy and solution, UBO documentation and an operating model description. EMIs that specialise in digital-asset clients have established review processes for this material. The onboarding timeline varies by institution and the completeness of the submission; incomplete submissions are the most common cause of delay.
What does client-money safeguarding require?
Client-money safeguarding requires a regulated entity to hold client funds in a manner that segregates them from the firm's own assets and protects them in the event of the firm's insolvency. Under MiCA and equivalent e-money regimes, this typically means holding client funds in a designated safeguarding account at an authorised credit institution or investing them in secure, liquid assets in accordance with the applicable regulatory rules. The specific requirements – account structure, notification obligations, reconciliation frequency – vary by regime and licence category. Failure to meet safeguarding requirements is a distinct regulatory risk that banks and EMIs assess as part of their onboarding review.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses – not retail clients. We map the licence, banking and compliance stack across the operating, custody and payment layers before you commit, so the structure holds when it is tested. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialises in VASP and CASP compliance programme design and banking-access strategy for digital-asset businesses across the EU, UAE and offshore jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.