De-risking – the practice by which a bank or electronic money institution (EMI) terminates or refuses a relationship to reduce its perceived regulatory exposure – has become the single most disruptive operational risk for digital-asset businesses. A licensed exchange with a clean compliance record can lose its euro SEPA rails without warning. A custodian completing a Series B can find its correspondent account closed before the round closes. When fiat rails go dark, the business stops.
The legal question is precise: what rights does a virtual asset service provider (VASP) have when a bank exercises de-risking, and what structural and procedural steps improve both the chance of retention and the speed of replacement? The answer turns on the applicable banking regime, the jurisdiction of the account-holding institution, the VASP's own licence posture, and – critically – the cross-border interaction between all three.
This analysis covers the regulated basis for de-risking, the defence process, the most common structural mistakes, the cross-border dimension that operators miss, and a decision matrix for businesses at different stages of the account-closure cycle.
What de-risking is, and why it disproportionately targets digital-asset businesses
De-risking is a deliberate business decision by a financial institution to exit a customer category rather than manage its risk individually. It is not a regulatory sanction. No regulator orders a bank to close a VASP account. The closure is a private contractual act – but it is typically driven by supervisory pressure, correspondent-bank requirements, or internal risk-appetite policies shaped by guidance from FATF (the Financial Action Task Force) and domestic AML supervisors.
Digital-asset businesses attract de-risking for a cluster of reasons that are structural, not individual. First, crypto transaction flows are harder for a bank's legacy transaction-monitoring systems to classify. Second, correspondent banks – which clear the hard-currency legs of international payments – impose their own risk categories on downstream banks, and "crypto" is frequently a prohibited or restricted category at the correspondent tier. Third, the licensing status of many VASPs is genuinely unclear to a bank's compliance team, particularly where the VASP holds a registration in one jurisdiction but serves clients across many others. Fourth, regulators have fined banks for AML failures linked to crypto clients; the reputational residue of those fines shapes bank behaviour for years afterward.
In our practice, operators that have suffered account closure most often held a single registration – sometimes a legacy EU VASP registration pre-MiCA, sometimes a payments institution licence in a single member state – while their actual user base, treasury flows and banking relationships spanned four or five jurisdictions. That mismatch is the proximate cause of the bank's unease, whether or not it is articulated in the closure notice.
What is the legal basis for account closure, and what rights does a VASP have?
A bank's right to terminate a business account is governed by the contract between the parties and by the applicable domestic banking law – not by a specific regulatory regime that uniformly protects VASPs. In most leading jurisdictions, a bank may close a business account on notice, typically a period measured in weeks rather than days, without giving reasons. That notice period is often the only procedural protection available in contract.
The more useful legal levers sit elsewhere. Under MiCA and the EU payment-services directives, certain obligations apply to payment institutions and to the access VASPs have to payment infrastructure. Where a licensed CASP (crypto-asset service provider) under MiCA is refused access to payment services on discriminatory grounds, there may be a basis to challenge that refusal through the relevant national competent authority. The practical difficulty is that the process is slow relative to the urgency of the closure.
In the United Kingdom, the FCA's cryptoasset registration regime under the Money Laundering Regulations does not itself compel a bank to serve a registered VASP. However, a registered VASP is in a materially stronger position when engaging the bank's compliance function, because it can demonstrate regulatory visibility in a recognised framework. Operators we advise have found that a well-documented regulatory file – showing the applicable regime, the AML programme, the transaction-monitoring methodology and the beneficial ownership structure – resolves a threatened closure more often than any formal legal challenge.
The cross-border dimension amplifies the difficulty. A VASP incorporated in one EU member state but banking through a third-country institution, while serving retail clients in a second member state, may find that none of the three jurisdictions offers a fast, effective route to compel account restoration. The practical defence is almost always structural: improve the compliance presentation before the notice period expires.
To map the specific rights available in your account-holding jurisdiction and to build the compliance file that changes the bank's calculus, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis.
How do you defend a bank account before the closure date?
Effective account-closure defence operates on two parallel tracks: the compliance engagement track and the replacement banking track. Running only one of them is the single most common mistake operators make.
On the compliance engagement track, the first step is to request a specific reason for the closure. Banks are not legally obliged to give one in most jurisdictions, but many will share a compliance concern informally rather than face a formal escalation. That concern – whether it is a missing document, an unresolved UBO query, a transaction pattern that triggered a rule, or a categorical policy against crypto – determines the response. A categorical policy is difficult to shift in the short term; a documentation gap is fixable within days.
The compliance file assembled for a retention engagement typically includes: a current corporate structure chart showing all beneficial owners above the applicable threshold; the VASP's licence or registration certificate in the relevant jurisdiction; a summary of the AML/CFT programme, including the Travel Rule (the obligation to pass originator and beneficiary data with a virtual asset transfer) compliance posture; a transaction-monitoring methodology note; and a client-risk classification summary. The bank's compliance officer needs to be able to sign off that the account is manageable. The file's function is to make that sign-off easy.
On the replacement banking track, the search for an alternative institution must begin on day one of the notice period – not at its expiry. The universe of banks willing to serve VASPs is narrower than it was five years ago in some jurisdictions and wider in others. EMIs licensed under the EU's payment-services regime have filled part of the gap, though they carry their own Travel Rule obligations and their own correspondent-bank constraints. In our cross-border practice, we see consistent demand for accounts in jurisdictions where the regulator has issued clear guidance on VASP onboarding: the AFSA regime within the AIFC in Kazakhstan, the ADGM/FSRA framework in Abu Dhabi, and selected EU member states where national competent authorities have maintained active VASP supervision through the MiCA transition.
Can an EMI replace a bank account for a digital-asset business?
An EMI is a regulated entity licensed to issue electronic money and provide payment services; it can provide IBANs, SEPA and SWIFT payment access, and – in some cases – multi-currency settlement. For a VASP that cannot obtain or retain a commercial bank account, an EMI may serve as a functional equivalent for most payment flows, though with important limitations.
EMI onboarding for a digital-asset business is itself a regulated compliance exercise. The EMI must apply its own AML and customer-due-diligence obligations, which means the VASP undergoes a thorough onboarding review. The documents required broadly mirror those in a bank's CDD process: corporate structure, licensing evidence, business model description, projected transaction volumes by counterparty type, AML programme summary, and source-of-funds documentation for the founding shareholders. The depth of scrutiny varies by the EMI's own risk appetite, its correspondent-banking relationships, and the jurisdiction in which it is licensed.
Under MiCA and the EU payment-services framework, an EMI operating under a passported EU licence can provide payment services across the EEA to a VASP client. However, the EMI's correspondent bank may still impose restrictions at the settlement layer. We have seen situations in which an EMI successfully onboarded a crypto exchange, only for the correspondent to restrict the VASP's transaction categories within months. The structural solution is to build redundancy across at least two EMIs in different jurisdictions rather than treating a single EMI relationship as a solved problem.
The cost dimension matters. EMIs typically price services on a per-transaction basis rather than a flat monthly fee, and for a high-volume exchange, the cost of fiat settlement through an EMI can materially exceed what a direct bank relationship would have cost. That commercial reality is part of the planning analysis, not a reason to avoid EMI onboarding.
What structural mistakes cause de-risking across borders?
The most consequential mistake is licensing in one jurisdiction while operating economically in several others. A VASP registered under the Bank of Lithuania's supervision before the MiCA transition, for instance, was not thereby licensed to provide crypto-asset services to retail clients in Germany, France or Spain. If the bank holding the account is in one of those markets, its compliance team will see a mismatch between the licensing claim and the actual business flow.
The second common mistake is inadequate beneficial ownership documentation at the level the bank actually requires. Most operator compliance files are built for the VASP regulator, not for a commercial bank's enhanced-due-diligence unit. Those are different audiences with different expectations. A regulator reviews the file once at authorisation. A bank's compliance team reviews it every year, against a refreshed set of internal standards. Operators that update their regulatory filing but not their banking CDD package accumulate documentation risk over time.
The third mistake is treating the Travel Rule as a compliance checkbox rather than a technical infrastructure question. A VASP that cannot demonstrate – in writing, with a named solution – how it captures and transmits originator and beneficiary data for virtual asset transfers will fail an EMI's enhanced onboarding review. Travel Rule compliance is now a standard due-diligence line item for any financial institution serving a VASP.
Fourth: a single jurisdiction, single bank, single currency stack. The VASP that banks exclusively through one institution in one jurisdiction has no resilience when that institution de-risks the sector. The cross-border planning work – entity structure, jurisdiction selection, account diversification – should be done before the licence application is filed, not after the first closure notice arrives.
Decision matrix: which path fits your situation?
The right defence and replacement strategy depends on where the business is in the de-risking cycle and what its current licensing posture looks like.
Profile A: Licensed CASP under MiCA or a comparable regime, account closed with notice outstanding. The primary track is the compliance-file engagement: a comprehensive CDD package delivered to the bank's compliance officer, a direct escalation above the relationship manager, and – simultaneously – outreach to EMIs in at least two EU/EEA jurisdictions. The notice period is the working window. The risk is that the bank's policy is categorical and engagement will not reverse it; the parallel replacement track is therefore mandatory from day one. Indicative timeline: replacement banking in place within four to six weeks if the compliance file is complete.
Profile B: Registered or partially licensed VASP, account closed without prior notice, operating in multiple jurisdictions. The immediate priority is emergency fiat liquidity: identifying which existing payment relationships can absorb settlement volume while the banking gap is addressed. The structural question is the licensing posture: if the entity's licence does not match its actual operating footprint, the replacement bank will identify the same mismatch. A licensing gap analysis must run in parallel with the account-replacement work. The timeline is longer and the risk is higher; a licensing remediation in a new jurisdiction typically takes a matter of months, not weeks.
Profile C: Early-stage business, no current bank account, structuring from scratch. This is the most manageable position. The entity structure, jurisdiction of incorporation, licence choice and banking selection should be planned together. A jurisdiction with an active VASP licensing regime and established EMI access – such as those within the EU MiCA regime or the AIFC/AFSA environment in Kazakhstan – reduces the risk of de-risking at the first banking stage. The target is a multi-institution, multi-jurisdiction banking stack from inception.
What does client-money safeguarding require in a de-risking scenario?
Client-money safeguarding obligations do not pause during an account-closure event. A VASP or EMI that holds client funds in a safeguarding account – a requirement under most leading payment-services and EMI regimes, including the EU framework – must maintain those funds in a qualifying account at an authorised credit institution at all times. The loss of a safeguarding account is therefore a regulatory breach, not merely a commercial inconvenience.
In practice, this means that the replacement-banking track for a licensed EMI or regulated payment institution must prioritise the safeguarding account above all other account types. The institution's regulator will expect immediate notification of a material risk to safeguarding compliance. Delay in notification is itself a breach in most frameworks. We regularly advise clients on the sequencing: notify the regulator promptly, establish interim safeguarding arrangements using an alternative qualifying institution, and document the contingency-planning steps taken.
The cross-border dimension here is acute. A VASP incorporated in one jurisdiction but holding a safeguarding account at a bank in another may find that the safeguarding obligations of the first jurisdiction require specific account structures or wording that the second jurisdiction's banks do not offer as standard. That structural mismatch is a known failure point. In our practice, we resolve it during the initial licence application phase rather than after the banking relationship breaks down.
If your safeguarding account is at risk or your current structure does not meet the applicable regime's requirements, the time to act is before the notice period expires. Write to our team at info@oboluslaw.com or message us via t.me/oboluslaw.
How this works in practice: a recent matter
In a recent engagement, a stablecoin-adjacent payments operator holding a payment institution licence in one EU member state found that its primary euro-settlement bank had issued a 60-day closure notice, citing a categorical internal policy change. The operator's client-money safeguarding account and its own-funds account were both held at the same institution. We were engaged on day three of the notice period. We assembled a full CDD and regulatory file within five business days, made a direct compliance-level engagement with the bank, and initiated parallel onboarding processes with three EMIs in two jurisdictions. The bank's categorical policy did not shift. However, a replacement safeguarding account was established at an alternative qualifying institution before the notice period expired, and the operator's full settlement volume was migrated without a breach of the applicable safeguarding regime. The compliance regulator was notified at day seven and closed its monitoring engagement without action.
A common assumption: one licence is enough
A common assumption among operators entering digital-asset markets is that a single offshore registration – a BVI VASP registration under the BVI FSC regime, for instance, or a Cayman registration under the CIMA VASP Act – is sufficient to serve clients globally and satisfy any bank's compliance requirements. It is not. An offshore registration addresses the VASP's home-jurisdiction obligation. It does not constitute a licence to solicit clients in the EU, the UK, Singapore or Hong Kong. And it does not tell a bank's compliance officer anything about how the business manages AML risk in the jurisdictions where its clients actually sit.
The practical consequence is predictable. The bank onboards the VASP against the offshore registration, the account grows, the transaction flows show a multi-jurisdictional client base, the bank's next periodic review flags the mismatch, and the account is de-risked. The operator then discovers that rebuilding the banking relationship requires rebuilding the licence structure first. That process takes time the business cannot always afford.
The correct architecture starts with a licensing analysis that matches the entity's actual operating scope – which jurisdictions generate revenue, which jurisdictions hold client assets, which jurisdictions process payments – and then selects the licence stack that covers that scope. In our experience, this analysis almost always reveals that the business needs at minimum two regulated presences: one in the jurisdiction of primary operation, one in the jurisdiction of primary payment infrastructure. The banking and EMI selection follows from that structure, not the other way around.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital-Asset Businesses – the full practice overview covering account strategy, EMI selection and payment licensing across leading jurisdictions.
- Corporate Bank Account Opening for Early-Stage Founders – a step-by-step guide for pre-revenue and seed-stage crypto businesses building their first banking stack.
- VASP Business Risk Assessment in Canada – jurisdiction-specific analysis of the VASP risk framework under Canadian AML supervision, relevant for North American banking access.
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily for risk-management reasons rather than as a regulatory sanction. Correspondent-bank restrictions, internal AML policy changes, inadequate customer due diligence documentation, licensing mismatches between the VASP's registration and its actual operating scope, and transaction-monitoring system limitations are the most common triggers. The closure is contractual and typically requires only a notice period; the practical defence is a strong compliance file and a parallel replacement strategy initiated immediately.
How can a VASP onboard with an EMI?
A VASP seeking EMI onboarding must present a complete corporate structure with beneficial ownership information, evidence of its applicable licence or registration, a written AML programme summary including its Travel Rule compliance posture, projected transaction volumes by counterparty type, and source-of-funds documentation for founders. The EMI applies its own customer-due-diligence and AML obligations to the VASP as a business client. Onboarding timelines vary by EMI and by the completeness of the file presented; a well-prepared submission materially shortens the process.
What does client-money safeguarding require?
Under the payment-services and EMI regimes in leading jurisdictions, regulated firms holding client funds must keep those funds in a qualifying safeguarding account at an authorised credit institution, segregated from own funds at all times. If a safeguarding account is threatened by de-risking, the applicable regulator must be notified promptly and an alternative qualifying account established before the original account closes. Failure to maintain compliant safeguarding arrangements is a regulatory breach, regardless of the reason for the banking disruption.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than 70 jurisdictions, on disputes and on-chain asset recovery across more than 25 forums, and on the banking, payment and compliance structures that sit around them. We map the licence stack across operating, custody and payment layers before you commit – so that the banking architecture matches the business from day one. Operators facing de-risking, account closure or EMI onboarding challenges can reach us at info@oboluslaw.com. Digital assets are the whole of our practice.
By Victor Olsen, Regulatory and Compliance Analyst – specialising in VASP licensing posture, AML programme architecture and the regulatory interactions that drive bank de-risking of digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.