Operating a virtual asset service provider without a stable fiat corridor is not merely inconvenient – it is existential. Banks close accounts, payment processors withdraw terms, and the business either stalls or migrates to rails that attract fresh regulatory scrutiny. For an established VASP, the risk is compounded: the firm already holds client funds, runs live settlement cycles and cannot afford a gap in coverage. The question is not whether to solve the EMI onboarding problem. The question is how to solve it structurally, across the jurisdictions where the entity sits, where its clients transact and where its banking relationships are maintained.
This page sets out the regulated basis for EMI onboarding (the process by which a VASP gains access to fiat rails through an e-money institution or equivalent payment account provider), the practical process for achieving it, the mistakes that derail applications by established operators, and the cross-border considerations that determine whether a payment relationship can be sustained.
Why Fiat Access Fails for Established VASPs
The most common reason an established VASP loses banking or EMI access is structural, not behavioral. The underlying entity does not present a clean, auditable picture of who it serves, what it moves and under what regulatory authority it operates. That structural gap triggers de-risking (the practice of financial institutions withdrawing services from entire customer categories to reduce regulatory exposure), and once it begins it accelerates. A relationship that took months to build is terminated in days.
In our practice, we see this pattern across established operators in all of the major licensing hubs. A firm holds a VASP registration in one jurisdiction, processes client transactions through a payment account opened in a second, and services users across a third. Each leg of that structure is individually defensible. Assembled without a clear compliance narrative, the arrangement reads as high-risk to a bank's financial-crime team. The bank exits.
The issue is compounded by the pace of regulatory change. Under MiCA, the EU is moving toward a unified CASP authorisation regime that sets expectations for own funds, governance and AML procedures. EMIs operating under that regime are required to apply corresponding due-diligence standards to their VASP counterparties. An operator whose compliance documentation was adequate eighteen months ago may no longer pass an EMI's onboarding review today.
A secondary failure mode – one we observe particularly in firms that have scaled quickly – is the mismatch between the licence held and the activities conducted. A VASP authorised for custody may be running settlement flows that look, to a payment institution's risk team, like exchange or transfer activity. That triggers additional disclosure requirements, sometimes a formal escalation to a compliance committee, and frequently account closure. The fix is not a better cover letter. It is a structural realignment of the entity, its licence scope and its payment relationships before the next onboarding attempt.
The process above describes the standard pattern. Your facts – the entity's licence, the user base, the volume profile – change the analysis materially. For a scoped assessment of your current position, contact OBOLUS at info@oboluslaw.com.
The Regulated Basis for EMI Onboarding
An EMI – an entity holding an e-money institution authorisation under an applicable payment services regime – issues electronic money and provides payment accounts. For a VASP, access to an EMI's infrastructure provides fiat on-ramps and off-ramps, client account segregation and, in certain structures, safeguarding of client funds. The relationship is bilateral: the VASP is both a regulated entity in its own right and a business customer of the EMI, subject to the EMI's own compliance obligations toward it.
The applicable regime governing the EMI's obligations varies by jurisdiction. Within the EU, EMIs are authorised and supervised under the e-money directive as transposed into national law, and many operate under passporting arrangements that extend their reach across member states. In the United Kingdom, the FCA regulates EMI authorisation under the Electronic Money Regulations. In Singapore, MAS applies a tiered licensing structure under the Payment Services Act that encompasses both EMI-equivalent functions and digital payment token services. In the UAE, VARA and the ADGM-FSRA framework govern payment activities alongside virtual-asset services.
The relevance for an established VASP is this: the EMI is not a passive conduit. It is a regulated entity with its own AML, KYC and transaction-monitoring obligations toward its business customers. When the VASP applies to onboard, it is, in effect, undergoing a regulated due-diligence process. The EMI must satisfy itself on the VASP's ownership structure, its regulatory status, its AML controls, its customer base and its transaction typology. Failing to present that picture compellingly – and in a format the EMI's compliance function can process – is the single most common reason onboarding fails for operators who, on paper, are fully compliant.
What Does the EMI Onboarding Process Look Like for a VASP?
The onboarding process for a VASP at an EMI is a structured compliance review, not a standard account-opening exercise. It proceeds in identifiable stages, each of which has a specific failure mode for operators who approach it without preparation.
The first stage is pre-qualification. The EMI assesses whether it will engage with VASPs at all, and if so, what licence categories, jurisdictions and volume profiles it accepts. Many EMIs operating in the EU apply informal internal policies that exclude certain VASP activity types or impose strict geographic restrictions on the VASP's user base. An established operator approaching the wrong EMI with the wrong entity wastes time it may not have if a payment relationship is already under notice.
The second stage is document submission. The EMI will request corporate structure charts, beneficial ownership declarations, regulatory licences and correspondence, AML policies, customer risk-assessment frameworks, transaction monitoring procedures, audited accounts, and often a sample of the VASP's own KYC documentation. For an established operator, the volume of documentation is manageable. The risk is that the documentation tells an inconsistent story – a licence that covers custody but policies that address exchange, or an AML framework written for one jurisdiction applied to a multi-jurisdictional user base.
The third stage is the compliance committee review. This is where most well-prepared applications fail. The EMI's committee is assessing risk, not compliance alone. It wants to understand the worst-case transaction that could flow through the account and whether the VASP's controls would catch it. An established operator needs to present not just the policy, but the evidence of its operation: SAR (suspicious activity report) filing history, transaction-monitoring tuning rationale, and the procedures for managing flagged transactions. Generic policy documents do not answer that question.
The fourth stage is ongoing monitoring. Once onboarded, the VASP should expect periodic review requests, transaction-level queries and, as the EMI's own regulatory environment evolves, requests to update documentation. The onboarding is not a one-time event. It is the entry point into a supervised relationship that requires active management.
In our practice, we prepare the complete documentation package for the EMI review and engage directly with the EMI's compliance team at each stage. We have seen applications succeed – and fail – on the quality of the narrative, not the quality of the underlying controls.
Cross-Border Complexity: Which EMI in Which Jurisdiction?
The EMI selection decision is, for an established operator, as important as the documentation preparation. Not all EMIs will onboard VASPs. Of those that will, the right one depends on the VASP's operational footprint, its licence stack and the currencies and corridors it needs to support.
A VASP with a MiCA-aligned CASP authorisation in Lithuania or Malta, serving EU clients and requiring Euro settlement, will typically look at EMIs passporting within the EU. The passporting regime means the EMI does not need local presence in each member state, but the VASP's own licensing position in those states matters for the compliance review. An operator whose entity is correctly licensed under the MiCA transition process presents a materially different risk profile to one still operating under a grandfathered VASP registration.
A VASP operating across the UAE will navigate a different structure. VARA regulates mainland Dubai virtual-asset activities, while ADGM under the FSRA framework governs activities within that free zone. Payment relationships in the UAE often involve EMI-equivalent licensed payment service providers operating under the UAE Central Bank regime – a separate authorization track from both VARA and ADGM. For an established operator, the practical question is whether the payment provider's authorisation covers the specific currencies and corridors the VASP requires, and whether the VASP's VARA licence category is one the payment provider will accept.
The Travel Rule – the obligation under FATF Recommendation 15 and its national implementations to pass originator and beneficiary data with virtual-asset transfers above applicable thresholds – adds a further dimension to EMI selection. EMIs that handle both fiat and the fiat leg of crypto transactions increasingly require their VASP counterparties to demonstrate a compliant Travel Rule solution. The solution must interoperate with the EMI's own data infrastructure, which varies by provider and jurisdiction.
Operators we advise routinely underestimate the number of jurisdictions that are operationally relevant to their payment structure. The entity is in one place. The clients are in another. The banking is in a third. Each of those loci carries its own AML, licensing and data-transfer obligations, and the EMI relationship must be structured to address all three. Allied counsel in the relevant jurisdiction assists where local regulatory engagement is required.
Common Mistakes That Derail Established Operators
An established VASP approaching EMI onboarding typically brings better underlying compliance than an early-stage operator. It also brings more complexity, more transaction history and, frequently, more baggage from prior banking relationships that ended badly. The mistakes we see most often are not failures of intent. They are failures of presentation and structure.
The first is entity proliferation without narrative. A VASP that has grown through multiple licensing jurisdictions often holds entities in three or four places, with payment relationships scattered across them. The EMI's compliance team cannot, without guidance, understand which entity is the principal operator, how client funds flow between them, and which regulatory authority is the lead supervisor. The onboarding application must answer those questions before they are asked.
The second is presenting compliance documentation that is not actually operated. The EMI will ask about transaction monitoring not as a box-checking exercise, but as a due-diligence inquiry. If the VASP's documented procedures include steps that are not performed in practice – escalation chains that do not function, thresholds that are set but not monitored – that gap will emerge during review and will end the application.
The third is approaching the wrong EMI. A common assumption among established operators is that any EMI that accepts crypto-related businesses will work for their structure. In practice, EMIs differ substantially in their appetite by VASP licence category, by the jurisdictions of the VASP's user base, by the currencies required and by the transaction volume profile. Applying to an EMI whose internal policy excludes the VASP's primary activity is a waste of time and, in some cases, a reputational signal to the broader market.
The fourth is failing to address a prior account closure proactively. If a previous payment relationship ended because the bank or EMI flagged a compliance concern, that event is likely to appear in industry data-sharing arrangements. Presenting a subsequent application without directly addressing what happened – and what has changed – guarantees that the new application will fail at the committee stage.
Decision Matrix: Which Structure for Which Operator Profile?
Established VASPs present different profiles, and the right EMI onboarding structure varies accordingly.
Profile A is the single-jurisdiction operator with a well-defined licence, a domestic client base and a clear transaction typology. For this profile, the onboarding process is relatively contained. The documentation package focuses on the licence, the AML controls and the transaction profile. The EMI selection is driven by currency coverage and corridor access. The timeline, if the package is well-prepared, is typically a matter of weeks rather than months – though this varies by EMI and by the complexity of the VASP's risk profile. The key risk for this profile is complacency: the operator assumes its existing compliance documentation is adequate without testing it against the EMI's specific requirements.
Profile B is the multi-jurisdiction operator with entities in several hubs, a cross-border client base and multiple licence categories. For this profile, the onboarding process is necessarily more involved. The priority is to establish a clear primary entity and payment relationship structure before approaching any EMI. The application must address entity relationships, fund flows, consolidated AML oversight and the regulatory status in each operational jurisdiction. The timeline is longer, and the EMI selection is more constrained – fewer EMIs will accept the full complexity of the structure. The key risk for this profile is attempting to onboard through a single entity while the broader structure remains unclear to the EMI's compliance team.
Profile C is the operator that has recently migrated from an offshore-only structure to a regulated hub presence. This profile carries the greatest onboarding risk. The prior offshore structure may have operated with AML controls that do not meet the standards applied in the new hub. The transaction history includes activity that, under the new regime's lens, would be classified differently. The EMI onboarding process for this profile requires a clean break – a rebuilt compliance framework, a documented transition narrative and, in some cases, a staged onboarding that starts with restricted activity and expands as the relationship matures. A single offshore licence has never been sufficient to serve clients globally; the EMI onboarding process makes that structural reality concrete.
If a prior application stalled or a payment account was closed, a second read of the structure can identify the reason and the route back. Write to OBOLUS at info@oboluslaw.com to discuss your position.
In Practice: Restoring Fiat Access After Account Closure
In a recent matter, an established payments and exchange VASP holding licences in two EU jurisdictions found its primary Euro account closed with short notice. The stated reason was "risk appetite," without further elaboration. The business had live settlement obligations and client withdrawal requests pending. We conducted a rapid structural review: mapped the entity's licence positions, identified that a secondary entity in the structure held a qualifying registration that had not been surfaced in the original onboarding, and rebuilt the documentation package around that entity. We engaged with two EMIs simultaneously, presenting a compliance narrative that directly addressed the transaction typology that had triggered the original closure. The business regained fiat access and completed its pending settlement obligations. The structural reorganization that emerged from that process also resolved a secondary licensing gap the operator had not previously identified.
Client-Money Safeguarding and the EMI Relationship
For an established VASP holding client funds, the EMI relationship is not only about payment processing. It is also the mechanism through which client-money safeguarding (the regulatory obligation to hold client funds separately from the firm's own assets, in a manner that protects those funds in an insolvency) is given practical effect. This obligation is distinct from the VASP's own licensing requirements and is governed by the payment services regime applicable to the EMI.
Where the EMI holds client funds on behalf of the VASP's customers, the safeguarding structure must meet the requirements of the applicable regime in the EMI's jurisdiction. Under EU payment services rules, EMIs must safeguard funds either by depositing them in a separate account at a credit institution or by covering them with an insurance policy. The VASP's obligation, in that structure, is to ensure that the EMI's safeguarding arrangements are adequate and correctly documented in the contractual relationship.
Where the VASP itself holds an EMI authorisation, it may safeguard client funds directly, subject to its own regulator's requirements. Ireland, as an EU member state with an established track record in EMI authorisation through the Central Bank of Ireland, is one jurisdiction where this structure is regularly implemented by digital-asset businesses seeking a passportable EU payment base. The applicable safeguarding obligations in that context are those set by the Central Bank of Ireland under the transposed EU payment services regime.
Regulators in the leading hubs increasingly expect VASPs to document, clearly and specifically, how client funds are held, under what regulatory authority and what happens to those funds in an insolvency event. An EMI onboarding process that does not address this question will produce a payment relationship that satisfies the VASP's settlement needs but leaves an unresolved gap in its compliance framework.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital Asset Businesses – the practice overview covering fiat access, payment licensing and banking strategy across jurisdictions.
- Client Funds Safeguarding in Ireland – the safeguarding regime under the Central Bank of Ireland for EMIs and payment institutions.
- EMI Onboarding for VASPs for Institutional Clients – onboarding considerations specific to institutional-grade VASPs and custody structures.
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily through de-risking – the decision to withdraw services from a customer category rather than manage the compliance exposure individually. The trigger is usually an inability to satisfy the bank's financial-crime team about the nature and origin of transactions, the regulatory status of the business, or the ultimate beneficial ownership. Structural presentation failures, not actual compliance failures, are the most common cause among established operators who hold valid licences.
How can a VASP onboard with an EMI?
A VASP onboards with an EMI by presenting a complete compliance package that addresses the EMI's specific due-diligence requirements: corporate structure, beneficial ownership, regulatory licences, AML policies, transaction monitoring evidence and a clear account of the user base and transaction typology. EMI selection matters as much as documentation quality. Not all EMIs accept VASPs, and those that do apply varying criteria by licence category, jurisdiction and volume profile. Legal preparation of the package materially increases the success rate.
What does client-money safeguarding require?
Client-money safeguarding requires a VASP – or the EMI through which it holds client funds – to maintain those funds separately from the firm's own assets and in a manner that protects them in an insolvency. The specific obligations depend on the applicable payment services regime: under EU rules, safeguarding is achieved by segregated deposit at a credit institution or equivalent insurance cover. The contractual arrangements between the VASP and its EMI must reflect these requirements explicitly.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – so that the structure works in the jurisdictions that matter, not just the one where the entity was incorporated. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory and Compliance Analyst – specialising in VASP licensing strategy, EMI onboarding frameworks and multi-jurisdictional compliance structuring for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.