For an early-stage VASP (virtual asset service provider), access to fiat rails is not a secondary concern – it is the operating condition that determines whether the business survives its first year. Banks close crypto company accounts without notice. Payment processors decline onboarding before a call is returned. Founders discover, often too late, that the entity structure they chose for tax efficiency is precisely the structure that triggers a compliance refusal. EMI onboarding – securing a live account relationship with a regulated electronic money institution (an EMI, a firm authorized to issue e-money and hold client funds in safeguarded accounts) – has become the critical path for every VASP that needs to move fiat at scale.
This page explains the regulated basis for EMI access, the practical application process, the structural mistakes that kill onboarding early, and the cross-border dimension that early-stage founders consistently underestimate. Where relevant, it maps the interaction with crypto banking, fiat rails, and the payment licence obligations that regulators increasingly attach to VASP operations.
Why Fiat Access Is a Regulated Question, Not a Commercial One
EMI onboarding for a VASP is not a standard business banking exercise – it is a compliance and regulatory positioning exercise that happens to produce a bank account. Every EMI operating under a recognized regime (the FCA in the UK, relevant national competent authorities under the EU's payment services framework, MAS in Singapore, or the ADGM's FSRA in Abu Dhabi) is required to conduct its own customer due diligence on business clients. A VASP is, by definition, a higher-risk client. The EMI's own regulator will scrutinize the quality of its VASP relationships. That tension drives the rejections founders experience.
The consequence is structural: the EMI is not deciding whether it likes your business. It is deciding whether it can defend onboarding you at its next supervisory examination. Founders who approach EMI onboarding as a sales process – pitching the growth story – are solving the wrong problem. The question the EMI's compliance team is asking is whether the VASP's own regulatory posture, AML controls, and transaction monitoring are defensible under the EMI's home-jurisdiction obligations.
Under the FATF Recommendation 15 framework (the FATF standard requiring jurisdictions to apply AML/CFT measures to virtual asset activities), VASPs carry an elevated risk classification. EMIs that onboard VASPs inherit a portion of that risk profile. Every regulator in the flagship payment hubs – the FCA, the relevant EU national competent authorities, MAS, the FSRA – expects EMIs to apply enhanced due diligence to VASP relationships. Understanding that dynamic is the first step toward a successful onboarding approach.
What EMIs Actually Assess During VASP Onboarding
An EMI's VASP onboarding assessment covers four broad dimensions, and failing on any one of them produces a rejection – typically with no explanation given. In our practice, we see founders declined not because their business is non-compliant but because the documentation they presented failed to communicate compliance in the register the EMI's compliance team recognizes.
The four dimensions are: regulatory status (does the VASP hold an applicable licence or registration, and in which jurisdiction); AML programme quality (is there a written policy, a named MLRO, a documented risk assessment, and a transaction monitoring process that the EMI can inspect); transaction flow intelligibility (can the VASP explain, with data, the source of its fiat inflows and the nature of its user base); and corporate structure transparency (is beneficial ownership clear, are group entities in jurisdictions the EMI considers acceptable, and are there no politically exposed persons or sanctioned-country connections that require explanation).
A fifth dimension – increasingly prominent under tightening supervision – is the VASP's own Travel Rule compliance posture. The Travel Rule (the FATF obligation requiring VASPs to pass originator and beneficiary identifying information with virtual asset transfers above the applicable threshold) is now an active EMI concern, not a theoretical one. EMIs ask whether the VASP has a Travel Rule solution deployed, which counterparty VASPs it transacts with, and whether those counterparties are regulated. A VASP that cannot answer this question in a compliance onboarding call will not progress.
For a scoped assessment of your current compliance posture and its presentability to an EMI, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis significantly for early-stage founders.
The Application Process: What Early-Stage Founders Should Expect
A well-prepared VASP onboarding application to an EMI moves through five identifiable stages, and the preparation phase – which most founders skip – is where the outcome is determined.
The first stage is EMI mapping: identifying which EMIs operate in the payment corridors the VASP needs, hold an appropriate licence for those corridors, and have a stated or demonstrable appetite for VASP clients. Not all licensed EMIs accept virtual asset businesses. Many that do accept VASPs impose activity restrictions – prohibiting custody-related flows, limiting jurisdictions, or capping transaction volumes. Founder time spent on an EMI with no VASP appetite is time lost.
The second stage is documentation assembly. The standard package for a VASP onboarding application covers corporate documents (certificate of incorporation, constitutional documents, beneficial ownership registry extract), regulatory status evidence (licence certificate, registration confirmation, correspondence with the regulator), an AML policy and risk assessment, a business overview including projected transaction volumes and source-of-funds narrative, and key-person identification documents. For early-stage founders, projected volume figures are estimates – but they must be credible estimates, anchored to a disclosed user acquisition plan, not aspirational numbers that an EMI's risk team cannot validate.
The third stage is compliance pre-screening. Most reputable EMIs have a pre-onboarding call or questionnaire stage. This is not a courtesy introduction – it is a live compliance assessment. The person on the call is evaluating whether the VASP's MLRO or compliance officer can speak fluently about the AML programme. Founders who handle this call without preparation, or without a qualified compliance voice in the room, routinely fail here. We regularly advise clients to treat the pre-screening call as the substantive hearing it is.
The fourth stage is formal application and review, which typically runs for a number of weeks depending on the EMI's queue and the complexity of the applicant's structure. During this period, the EMI may issue requests for additional information – each of which restarts or extends the review clock. Response quality at this stage matters as much as the original application.
The fifth stage is account activation and limit negotiation. Being approved is not the same as being operational. Early-stage VASPs are frequently subject to initial transaction limits, enhanced transaction reporting obligations, and periodic re-review requirements. Negotiating initial limits that accommodate the business's actual operating needs – rather than accepting default restrictions that constrain growth – is a step many founders overlook until they are live and constrained.
Structural Mistakes That Kill EMI Onboarding for Early-Stage VASPs
The most common reason early-stage founders fail EMI onboarding is a structural mismatch between the entity they chose and the entity an EMI can accept. This is often not fixable quickly – which is why structure choices made at formation have a banking dimension that most formation advisors do not address.
The first structural mistake is domicile mismatch. A holding company in a low-tax offshore jurisdiction operating a VASP that serves EU or UK customers through a subsidiary triggers a cross-border complexity that many mid-tier EMIs will not underwrite. The EMI's own regulator may scrutinize relationships with groups that hold material value in jurisdictions with limited AML supervision. This does not mean offshore structures are prohibited – it means they require a more sophisticated narrative and, often, a more sophisticated EMI relationship.
The second mistake is licensing gap. A founder who registered a legal entity and began operations on the assumption that a licence application was "in progress" has no regulatory status to present. Several EMIs will provisionally engage with a VASP that has applied for a licence and can show a live application reference, but the bar is higher than founders expect. An application that has been pending for an extended period without progress signals to the EMI that there may be substantive regulatory issues.
The third mistake is AML programme incompleteness. A Word-document AML policy downloaded from a template site does not constitute an AML programme. EMIs that onboard VASPs have seen every template in circulation. What they look for is evidence that the policy is implemented – transaction monitoring logs, a named MLRO who has completed relevant training, a risk assessment that reflects the actual client base and transaction typologies. The documentation gap here is common among early-stage founders who prioritized product over compliance infrastructure.
A fourth – and underappreciated – mistake is presenting a corporate structure that the EMI cannot map to a single ultimate beneficial owner. Complex multi-layered structures with discretionary trusts, nominee shareholders, or unclear voting arrangements generate automatic escalation flags. The EMI's compliance team will not resolve ambiguity in the applicant's favor.
The Cross-Border Dimension: Where the Entity Sits vs. Where Banking Lives
Early-stage VASPs routinely incorporate in one jurisdiction, license in a second, serve users in a third, and then discover that their banking options are determined by a fourth – the jurisdiction where a willing EMI operates. This four-way misalignment is the defining cross-border challenge of early-stage digital-asset company formation, and it is the dimension that a licensing-only adviser will not map.
We have seen founders structure correctly for tax and licensing purposes, only to find that the EMI-accessible payment corridor for their user geography runs through a jurisdiction where their entity has no registered presence and cannot easily establish one. The reverse is equally common: a founder who chose a jurisdiction for its VASP-friendly EMI environment discovers that the same jurisdiction's AML risk classification by the FATF or by the EU's own high-risk-country list creates downstream correspondent-banking friction that makes the fiat rails functionally unusable at scale.
The cross-border stack for a VASP needs to be modeled across at minimum three axes: the entity's regulatory home (which drives which regulators supervise it and which licence it holds), the payment corridor it needs to serve (EUR, GBP, USD, or multi-currency), and the jurisdictions of its primary user base (which drive AML classification for the EMI). Getting all three right simultaneously is not a routine incorporation exercise. It is a cross-practice legal and structuring engagement that maps the licence, banking, and compliance layers before the company commits to any structure.
In our cross-border practice, we see operators who entered one hub for its apparent EMI accessibility, only to find that serving users in a second market triggered a separate licensing obligation that the EMI's terms of service expressly excluded. The interaction between MiCA passporting (under which a CASP – crypto-asset service provider – authorised in one EU member state may passport across the EU/EEA) and the EMI relationships available to that entity in specific member states is a current live issue for EU-bound early-stage founders. Not all EU-passported CASPs find EMI relationships equally accessible across the member states into which they passport.
If your structure was built without a banking and EMI layer analysis, a second read can surface the misalignment before it becomes a live funding problem. Write to OBOLUS at info@oboluslaw.com or message via t.me/oboluslaw. If a prior EMI application stalled or an account was closed, the structural reason is almost always identifiable – and the route back exists.
Decision Matrix: Which EMI Profile Fits Which Early-Stage VASP
Early-stage VASPs are not a homogeneous group. The right EMI relationship depends on the VASP's licence status, geographic footprint, transaction typology, and volume profile. The following profiles represent the common configurations we encounter in practice.
Profile A – Pre-licence, EU-target VASP: A founder with a product ready and a CASP application filed in an EU member state needs interim fiat access for operational expenses (payroll, cloud, contractor payments) before the licence is granted. The available EMI set here is narrower – most regulated EMIs require at minimum a filed application with a live reference. Timelines to onboarding in this profile tend to extend, and initial transaction limits are restrictive. The key risk is that the founder's operating runway erodes during the wait. The correct approach is to begin EMI outreach immediately upon filing the CASP application, using the application reference as the regulatory anchor, while simultaneously ensuring the AML programme is in a form that can survive a compliance review.
Profile B – Licensed VASP, multi-currency need: A VASP holding a licence under the BVI VASP Act, Singapore's Payment Services Act, or the VARA regime in Dubai, seeking EUR and GBP corridors for EU and UK users, needs a different EMI profile than Profile A. The licensing credential is stronger. The cross-border complexity increases. EMIs operating under FCA or EU NCA supervision that accept licensed offshore VASPs as clients impose enhanced due diligence requirements and typically require a local entity or compliance officer in their jurisdiction. Timelines are typically measured in weeks from a complete application. The key risk is that the offshore structure triggers correspondent-banking friction downstream even after EMI onboarding is complete.
Profile C – Institutional VASP with custody function: A VASP that also holds client crypto assets under a custody arrangement faces the most demanding EMI onboarding environment. The combination of VASP operations and custody – particularly if the entity also processes client fiat withdrawals – requires the EMI to underwrite a complex risk profile. Only a subset of EMIs in the leading hubs have the internal risk infrastructure to manage this. For this profile, EMI onboarding is inseparable from the custody licensing question, and the two tracks need to run in parallel. Timelines vary substantially. The key risk is that a VASP approaches an EMI with a custody disclosure only after onboarding has progressed, triggering a re-review from the beginning.
A Common Assumption Worth Correcting
A common assumption among early-stage founders is that a single offshore licence is sufficient to serve clients globally and to open banking in any jurisdiction. This assumption is incorrect on both counts. The licence you hold determines where you are authorized to provide VASP services – not where your clients are, and not where an EMI will accept your business.
Serving users in the EU without a MiCA CASP authorisation (or, during the transitional period, an applicable national registration) exposes the VASP to enforcement action by national competent authorities, independent of where the entity is incorporated. Serving UK users without FCA registration under the Money Laundering Regulations creates a comparable exposure under the FCA regime. EMIs in these jurisdictions are aware of this. An application from an offshore-licensed VASP that discloses a material EU or UK user base will trigger a compliance escalation based on unauthorized provision of services – regardless of the applicant's licensing status at home.
The operating rule is that the licence stack follows the user, not the entity. For a VASP with users in multiple jurisdictions, the correct structure involves either a passportable authorization (such as a MiCA CASP that covers the EU user base) or a jurisdiction-by-jurisdiction licensing analysis that maps each user market to an applicable regime. That analysis is the predicate for any EMI onboarding exercise that will survive regulatory scrutiny over time. Operators we advise regularly discover, upon doing this analysis, that their actual addressable user market – the one they can lawfully serve from their current structure – is materially smaller than their initial business plan assumed.
What Client-Money Safeguarding Requires in This Context
Client-money safeguarding is an EMI-level obligation, but it has direct consequences for VASPs that hold fiat on behalf of clients in transit. Under most regulated payment frameworks – including the EU Payment Services Directive framework and the UK's equivalent – an EMI must safeguard client funds either by segregating them in a separate account at a credit institution or by holding eligible insurance or guarantee cover. For a VASP using an EMI to move client fiat, the safeguarding architecture determines where the regulatory risk sits and whether the VASP itself takes on any client-money obligation.
The specific risk for early-stage VASPs arises when the operational model involves the EMI holding fiat balances for the VASP's end clients, rather than purely for the VASP itself. That structure may bring the VASP within the scope of client-money rules in the jurisdictions where the end clients sit, independently of the EMI's own safeguarding obligations. Founders who do not distinguish between the VASP's own operational accounts (payroll, operating expenses, interchange) and accounts that hold client fiat pending withdrawal are building toward a regulatory classification they did not intend and may not be licensed to operate.
In a recent engagement, a payments company sought EMI access for what it described as a treasury function. On review, the account was structured to receive and hold client withdrawal queues – a safeguarding trigger in the relevant jurisdiction. We restructured the account architecture before the application was submitted. The company onboarded without the safeguarding compliance risk it had not initially identified. This type of pre-application architecture review is a standard step in our onboarding practice, and it routinely changes the framing of the application in ways that matter.
Related at OBOLUS
Related at OBOLUS
- Banking, Payments & EMI Onboarding for Digital-Asset Businesses – our full practice overview covering the regulated basis, EMI mapping, and account-opening strategy across leading payment hubs.
- Corporate Bank Account Opening Under Heightened Scrutiny – how to approach account opening when prior refusals, adverse press, or complex structures require a structured compliance narrative.
- EMI Onboarding for VASPs: Institutional Clients – the distinct onboarding considerations for VASPs serving institutional counterparties, including custody and clearing arrangements.
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because VASPs carry an elevated AML/CFT risk classification under FATF standards, and the bank's own regulator holds it accountable for the quality of its VASP relationships. Where a bank cannot satisfy itself that the VASP's AML programme, transaction monitoring, and Travel Rule compliance are adequate – or where the cost of enhanced due diligence exceeds the commercial return – it will exit the relationship. Account closures often reflect a strategic decision to exit a risk category, not a finding of specific misconduct.
How can a VASP onboard with an EMI?
A VASP can onboard with an EMI by presenting a complete, compliance-grade application package that includes: evidence of regulatory status (a licence, registration, or filed application with a reference), a documented AML programme with a named MLRO, a clear beneficial ownership structure, and a credible transaction flow narrative. The application process typically involves a pre-screening compliance call, a formal review period, and a negotiation of initial account limits. Preparation of this package – and selection of an EMI with demonstrable VASP appetite – is the determinative step.
What does client-money safeguarding require?
Client-money safeguarding, under most regulated EMI regimes, requires that the EMI segregate funds belonging to clients in a designated safeguarding account at a credit institution, or hold equivalent insurance cover. For a VASP using an EMI, the operational implication is that any account structure involving the EMI holding fiat on behalf of the VASP's end clients – rather than the VASP's own operational funds – may engage the EMI's safeguarding obligations and, depending on the structure, a separate client-money licence obligation for the VASP itself. The correct architecture depends on the VASP's transaction model and jurisdiction.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – so the structure you build is the structure your bank and EMI can accept. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in EMI onboarding strategy, AML programme structuring, and cross-border payment rail access for early-stage digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.