A crypto exchange or payment company discovers, often without prior warning, that its primary banking partner has issued a notice of account closure. The business has days – sometimes hours – to respond before fiat rails go dark and client settlements fail. De-risking and account closure defence under heightened scrutiny is the discipline of building the legal, structural and documentary position to prevent that outcome, or to recover from it when it occurs. This page sets out the regulated basis for bank-led de-risking, the defence process, the cross-border structural factors that determine whether a given banking relationship can survive escalating compliance scrutiny (the intensified review a financial institution applies to clients it categorises as high-risk), and the decision points at which external counsel changes the trajectory.
For digital-asset businesses, the loss of banking is not a commercial inconvenience – it is frequently an existential event. We advise operators across the full stack: the entity layer, the licence layer and the fiat rails (the banking and payment infrastructure through which a crypto business settles in national currency). Understanding how those three layers interact is the precondition for effective account-closure defence.
Why banks de-risk digital-asset businesses – and what the law actually requires
Banks close or refuse digital-asset accounts primarily because their own risk appetite – not a legal prohibition – places VASPs (virtual asset service providers) in a category that exceeds the institution's compliance tolerance. No major prudential regime mandates blanket exclusion of licensed crypto businesses. Yet the compliance costs of servicing a VASP, combined with regulatory pressure on banks to demonstrate tight AML/CFT controls, create a powerful commercial incentive to exit the relationship.
The operative legal regime for the bank is its national AML/CFT framework, which in turn reflects the FATF Recommendations – in particular Recommendation 15, which addresses virtual assets – and the customer due diligence obligations flowing from those standards. Banks in the EU apply AML directives administered by national competent authorities. Banks in the UAE apply the Central Bank of the UAE's AML requirements. The FCA in the UK supervises banks' compliance with the Money Laundering Regulations. None of these regimes instructs a bank to close a licensed VASP's account; all of them require the bank to understand its customer's business and satisfy itself that the AML controls are adequate.
In our practice, we see two categories of account closure. The first is a blanket policy exit, where the bank has made a sector-level decision to exit all crypto clients. The second – and the more defensible from the client's perspective – is a risk-appetite misalignment, where the bank's concerns are specific to the client's operating model, governance or documentation. Only the second category is practically addressable through a coordinated legal and compliance response.
The FATF Travel Rule – the obligation to pass originator and beneficiary data with a virtual-asset transfer – has sharpened bank-level scrutiny considerably. Operators that cannot demonstrate Travel Rule compliance with specificity are increasingly being exited, even in jurisdictions where the rule's local implementation is still maturing.
Reach the OBOLUS banking desk early. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. For a scoped assessment of your account-closure exposure, contact OBOLUS at info@oboluslaw.com.
What does heightened scrutiny actually look like in practice?
Heightened scrutiny is not a single event – it is a process, typically beginning with an Enhanced Due Diligence request and escalating toward account restriction or termination if the bank's concerns are not resolved. The stages follow a broadly consistent pattern across the major banking jurisdictions, though the specific procedural rights available to the client vary.
The first stage is an EDD questionnaire. The bank will request expanded documentation covering the client's beneficial ownership structure, the source of funds for the business, the nature of its customer base, its own AML/KYC policies, any regulatory licences held, and its transaction monitoring methodology. The completeness and coherence of this response is the single most important determinant of whether the relationship survives.
The second stage, where the initial response is inadequate or raises further questions, is an escalation to the bank's financial crime compliance team. At this point, the engagement shifts from a documentary exercise to an interview-style review. The bank may request a physical or virtual meeting with senior management, compliance officers or external counsel. Operators who attend without legal preparation routinely make disclosures that accelerate rather than prevent closure.
The third stage is formal notice of account restriction or termination. In most jurisdictions, a bank is not legally required to provide reasons for closing an account – though industry codes in certain markets create soft-law expectations of notice periods. Once notice is served, the practical window for remedy narrows sharply. A coordinated response at the second stage is nearly always more effective than a contested exit at the third.
In a recent matter, an EMI (electronic money institution) operating across three EU member states received simultaneous EDD requests from two correspondent banking partners after a routine transaction-monitoring alert. We prepared a unified response package covering governance, licence status, Travel Rule implementation, and a transaction-pattern narrative. Both relationships were preserved, and one institution subsequently approved an expansion of the account scope.
How does entity structure affect banking risk – and what should the model look like?
The jurisdiction in which a digital-asset business is incorporated, the jurisdiction in which it holds its operating licence and the jurisdiction in which it banks are three separate variables. Misalignment between them is the most common structural cause of banking vulnerability we encounter. A business incorporated in a low-regulation offshore jurisdiction, holding a VASP registration from a regime that lacks a credible AML supervisory track record, seeking to bank in a Tier 1 financial centre will face a compliance gap that no amount of EDD paperwork can bridge without structural change.
The cross-border dimension creates compounding risk. An exchange serving EU retail users from an entity outside the EU must consider not only its home-jurisdiction regulatory position but the applicable national frameworks in each user jurisdiction – and, increasingly, the expectations that EU banks apply to non-EU crypto counterparties under their own CASP-related risk policies. MiCA (the EU's Markets in Crypto-Assets Regulation), administered by ESMA and national competent authorities, is already influencing how EU-banking-relationship managers classify crypto clients, even for businesses that are not yet in scope for CASP authorisation.
The structural variables that most directly bear on banking viability are: the quality and jurisdiction of the primary operating licence; the transparency of the beneficial ownership chain; the existence of a dedicated compliance function with documented policies; the technical implementation of the Travel Rule; and the geographic profile of the underlying user base. Banks in the leading hubs – including institutions operating under FCA, FINMA and MAS supervision – have become substantially more sophisticated in assessing these factors.
For operators whose current structure creates an irresolvable banking conflict, the realistic response is a structural migration rather than a document exercise. That typically means establishing an operating entity in a jurisdiction whose licence is recognised as credible by the target banking market – a MiCA-authorised CASP in an EU member state for EU banking, a VARA-licensed entity for UAE banking, an MAS-regulated entity for Singapore banking, or an ADGM FSRA-regulated entity for Abu Dhabi and the wider Gulf. We map that transition as part of a broader licence, banking and tax stack review.
What are the most common mistakes businesses make when defending an account closure?
The most consequential mistake is silence. Operators who receive an EDD request and respond slowly, incompletely or through non-specialist staff signal to the bank that their compliance function is not operating at the standard required. Banks are accustomed to working with well-governed financial services businesses. A disorganised or partial response confirms, rather than rebutts, the risk assessment that triggered the review.
The second most common mistake is over-disclosure. In an attempt to appear cooperative, operators share documents that raise new concerns – internal compliance reports documenting past failures, policy drafts that are not yet implemented, or transaction data without the explanatory narrative needed to contextualise it. EDD responses should be complete, but they should be curated and supported by a legal and compliance analysis of each item before disclosure.
A third category of error arises in the cross-border context: inconsistency between what the business tells one banking partner and what it has disclosed to another, or between the EDD response and the regulatory filings in the home jurisdiction. Banks increasingly share adverse information about crypto clients through industry networks. Internal inconsistency, when identified, is rarely recoverable.
A common assumption among operators is that holding any regulatory licence – even a lightweight registration in a jurisdiction with limited supervisory capacity – provides meaningful protection against banking de-risking. It does not. The quality and credibility of the licence, assessed against the bank's own risk policies, is what matters. A registration that a bank's compliance team cannot verify or contextualise may worsen the risk profile rather than improve it.
If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. To discuss a live account-closure situation, contact OBOLUS at info@oboluslaw.com.
How does EMI onboarding work for VASPs – and where does it fit in the payment stack?
For digital-asset businesses that cannot obtain or maintain a direct bank account, an EMI relationship – with a licensed electronic money institution, supervised under the applicable EMI regime in its home jurisdiction – provides a regulated alternative for holding client funds and executing payment transactions. EMI onboarding follows a broadly similar EDD process to commercial banking, but the risk tolerance of the EMI market is structurally different.
EMIs that have built their client base in the fintech and digital-asset sector have developed compliance frameworks calibrated to VASP risk. They expect to see a VASP licence or equivalent registration, a Travel Rule technical solution, a documented transaction-monitoring methodology and a clear source-of-funds narrative for the underlying customer base. Operators that can provide this documentation in a structured format – rather than responding reactively to ad hoc requests – move through onboarding substantially faster.
The cross-border payment-licence layer matters here. An EMI authorised in one EU member state has the right to passport its services across the EU/EEA. This means that a VASP banking with an EU EMI obtains, in principle, settlement access across the entire EU market. But passporting rights do not eliminate host-state compliance obligations, and an EMI relationship does not substitute for the operating licences required in jurisdictions where the VASP serves users. The two layers – the payment licence supporting the fiat rail, and the VASP licence authorising the digital-asset activity – must be consistent with each other.
Client-money safeguarding is a specific obligation that applies to licensed EMIs. Under the applicable EMI frameworks, client funds must be segregated from the institution's own assets and held in safeguarding accounts – typically with a credit institution or in designated government securities. For VASPs that use an EMI as their banking layer, this means the EMI's own safeguarding structure is directly relevant to the security of the VASP's client balances. We regularly advise operators on reviewing that structure as part of the banking engagement.
Which structure fits which operator profile?
The right banking and payment structure depends on the operator's regulatory status, geographic footprint and the nature of the assets and flows it handles. The following profiles capture the most common decision points we encounter.
Profile A – Early-stage VASP, limited regulatory history, seeking EU market access. The initial banking path is typically through an EMI with a VASP-specific onboarding programme, supported by a CASP application in a credible EU member state. The EMI relationship provides immediate fiat settlement capacity; the CASP authorisation provides the regulatory foundation needed to support a bank-direct relationship over the medium term. The primary risk at this stage is over-reliance on a single EMI that itself carries concentration risk – a risk that has materialised repeatedly in the sector when mid-market EMIs exit crypto clients under their own banking pressure.
Profile B – Licensed exchange with EU users, banking relationship under EDD pressure. The priority is an immediate assessment of the gap between what the current documentation says and what the bank's compliance team is actually assessing. In most cases, the gap is addressable through a structured response package – governance documentation, a Travel Rule technical summary, a transaction-pattern narrative and a remediation roadmap for any identified control gaps. Where the bank's concerns reflect a sector-level policy rather than client-specific risk, the analysis shifts to identifying alternative banking options while the primary relationship is negotiated.
Profile C – Multi-jurisdiction operator with inconsistent entity structure. Banking de-risking in this profile typically reflects structural rather than documentary issues. The operator has entities in multiple jurisdictions holding different licences, with flows that cross the entity boundaries in ways that are difficult to explain under EDD scrutiny. The remedy is a structural rationalisation – mapping the licence, banking and tax stack across all operating entities and eliminating inconsistencies that create compliance gaps. We map the licence, banking and tax stack before you commit to a restructuring path.
Self-assessment: is your banking position defensible?
Before an EDD request arrives, the following questions indicate whether a digital-asset business is likely to survive heightened scrutiny from a banking partner. This is not an exhaustive legal audit – it is a preliminary indicator.
Does the business hold a regulatory licence or registration that is recognised as credible by Tier 1 banks in the target banking market? If the answer is qualified or uncertain, the banking position is vulnerable by definition.
Is the beneficial ownership structure documented to ultimate beneficial owner level, with current and consistent information across all regulatory filings? Discrepancies between the corporate registry, the regulatory licence and the EDD file are among the most frequently cited grounds for account restriction.
Does the business have a documented AML/KYC policy, a functioning transaction-monitoring system, and evidence that both are operative – not aspirational? Banks request testing records and compliance reports, not policy documents alone.
Has the business implemented a Travel Rule technical solution, and can it demonstrate that the solution is live and producing accurate data? In the leading banking hubs, Travel Rule non-compliance is a near-automatic trigger for EDD escalation.
Is the business able to produce a coherent source-of-funds narrative for its own treasury and for the customer flows it processes? Banks apply substance-over-form analysis; a narrative that conflicts with transaction data will not survive scrutiny.
If the answer to any of these questions is no, or uncertain, the business should treat that as a planning horizon – not a fact to conceal in an EDD response.
Related at OBOLUS
- Banking and EMI onboarding for digital-asset businesses – full practice overview covering account strategy, payment licence and fiat rail structuring
- PSP and acquiring agreements in the BVI – payment service provider structures and acquiring agreements under BVI law
- Oracle and data-feed liability in the Cayman Islands – liability exposure for data-dependent digital-asset products under Cayman law
FAQ
Why do banks close crypto company accounts?
Banks close or restrict digital-asset company accounts primarily because the cost and complexity of servicing a VASP exceeds the institution's internal risk tolerance – not because any law requires exclusion. The operative factors are the quality of the client's regulatory licence, the transparency of its beneficial ownership structure, its AML and Travel Rule compliance posture, and the geographic profile of its user base. Blanket policy exits and client-specific risk-appetite closures require different responses.
How can a VASP onboard with an EMI?
An EMI onboarding for a VASP typically requires a valid regulatory licence or registration, a documented AML and KYC policy, evidence of a live Travel Rule technical solution, a source-of-funds narrative for the customer base and a clear corporate ownership structure. EMIs with VASP-specialist compliance teams move faster where documentation is structured and complete. The EMI relationship supports fiat settlement but does not substitute for the operating licences required in the VASP's user jurisdictions.
What does client-money safeguarding require?
Under the EMI regimes in the leading jurisdictions, an electronic money institution must segregate client funds from its own assets and hold them in designated safeguarding accounts – typically at a credit institution or in approved government securities. For a VASP using an EMI as its banking layer, the EMI's safeguarding structure directly affects the security of client balances. VASPs should review the EMI's safeguarding arrangements as part of the onboarding assessment, not as an afterthought.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP licensing, AML/CFT compliance and banking-relationship strategy for digital-asset operators across the EU, UAE and leading offshore hubs.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.