For a virtual asset service provider (VASP) serving institutional clients, the gap between a regulatory licence and actual operating capability is almost always a payment account. A VASP can hold every approval its home regulator requires and still find that no electronic money institution (EMI) – a regulated entity authorised to issue electronic money and hold client funds on payment accounts – will open an account, process settlements or pass fiat in or out. When that gap appears at scale, with seven-figure settlement flows and a counterparty list of funds, family offices and prime brokers expecting T+1 liquidity, the exposure is not merely inconvenient. It is existential.
This page sets out how institutional VASPs structure EMI onboarding, which regulatory regimes govern the process, where the process fails and what counsel can do to move it forward. The analysis draws on the cross-border reality that most institutional digital-asset businesses face: an entity domiciled in one jurisdiction, users and counterparties in several others, and banking that must bridge all of them.
Why EMI Onboarding Is the Critical Path for Institutional VASPs
EMI onboarding is, in practice, the last legal gateway between a licensed VASP and full operational capability. A VASP licence – whether under VARA in Dubai, the MiCA CASP authorisation in the EU, or the MAS Payment Services Act in Singapore – authorises the regulated activity. It does not, by itself, open fiat rails. The EMI relationship does that. Without it, a VASP cannot receive institutional subscription proceeds, settle redemptions in fiat or hold segregated client balances in a compliant payment structure.
Institutional clients impose an additional filter. A regulated fund or prime broker will not route settlement flows through an account that cannot demonstrate: a named, supervised EMI counterparty; documented client-money safeguarding (the regulatory obligation to hold client funds separate from own funds, in a qualifying credit institution or in qualifying liquid assets); and an auditable reconciliation process. VASPs that cannot show that structure do not get the mandate.
The regulatory basis varies by hub. Under MiCA, an EMI operating in the EU must hold a licence from its home national competent authority and may passport the payment account service across the EEA – a structural advantage for VASPs with EU institutional counterparties. In the UAE, the overlap between VARA's activity-based regime and the Central Bank of the UAE's payment-institution supervision creates a two-regulator dynamic that affects account structure. In Singapore, MAS supervises both the VASP's DPT licence and the payment institution that services it, which tightens the documentation loop but simplifies the supervisory conversation. In each case, counsel must read the payment layer and the VASP licence together – not sequentially.
The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. For a scoped assessment of your EMI structure, contact OBOLUS at info@oboluslaw.com.
How EMIs Assess VASP Clients: The Institutional Risk Lens
EMIs apply a risk-based onboarding model that is more demanding for VASPs than for most other regulated-sector clients, and more demanding still when the VASP's clients are themselves institutional.
The first filter is jurisdictional. An EMI subject to EU AML obligations – whether under the applicable anti-money-laundering directives or the FATF Recommendation 15 framework governing virtual-asset businesses – will assess where the VASP is licensed, which regulator supervises it, and whether that regulator applies FATF-equivalent standards. A VASP licensed in a jurisdiction that FATF has identified as having strategic deficiencies is, in practice, unlicensable at most EMIs regardless of its internal compliance programme.
The second filter is structural. EMIs look at the VASP's corporate structure, its ownership and control, and – critically for institutional VASPs – whether the business model involves holding client assets. A VASP that holds client crypto-assets in custody and also processes fiat settlements presents a concentration of activity that many EMIs manage by requiring clear operational separation: a custody entity, a trading or exchange entity and a payment entity, each with its own regulatory perimeter.
The third filter is the Travel Rule – the obligation, implemented across FATF-member jurisdictions, to pass originator and beneficiary identifying information alongside a virtual asset transfer above the applicable threshold. EMIs increasingly require VASPs to demonstrate Travel Rule compliance – a functioning VASP-to-VASP data-sharing mechanism – before onboarding. Without it, the EMI cannot satisfy its own AML obligations when the VASP's settlement flows hit the payment account.
In our cross-border practice, we have seen EMI applications stall at each of these three filters in sequence: a VASP clears the jurisdictional screen, then fails on structure, then re-applies with a restructured entity and fails on Travel Rule documentation. The pattern is expensive. Addressing all three in preparation – before the first application – is materially faster and less costly than working through them reactively.
What Does the EMI Onboarding Process Actually Involve?
EMI onboarding for an institutional VASP is a structured due-diligence process that typically runs in four sequential stages, each generating documentation that feeds the next.
Stage one: pre-application readiness. Before submitting any application, the VASP must assemble the legal pack the EMI will request. This includes the VASP's regulatory authorisation and its home-regulator supervision correspondence, the corporate structure chart showing all entities and beneficial owners above the applicable threshold, the AML/KYC policy suite (including Travel Rule implementation evidence), and a business model description that accurately characterises the institutional client base and the expected settlement flows. Institutional VASPs should also prepare a safeguarding model document that shows how client fiat balances will be held and reconciled – this is the document institutional counterparties will ask to see independently.
Stage two: EMI selection. Not all EMIs will bank VASPs. Of those that will, a subset will accept institutional settlement flows above a given volume threshold, and a further subset will accept the jurisdictional and structural profile of any specific VASP. The selection process is not a matter of applying to a ranked list. It involves a prior mapping of which EMIs are authorised in the relevant jurisdictions, which have demonstrated VASP-sector experience and which have the clearing and correspondent relationships the VASP's settlement currency mix requires. Applying to an EMI without this mapping wastes weeks and generates a declination that sits on the VASP's onboarding record.
Stage three: application and enhanced due diligence. The formal application triggers the EMI's EDD process. For institutional VASPs, EDD typically includes: a request for the VASP's last audited financial statements; a review of the institutional client list (sometimes requiring disclosure of counterparty categories); a transaction-monitoring questionnaire; and a call between the EMI's compliance team and the VASP's MLRO. The timeline for this stage varies considerably by EMI and jurisdiction – from a matter of weeks at a specialist crypto-sector EMI to several months at a traditional payment institution.
Stage four: account structure and operational integration. Approval does not end the process. The VASP must then configure the account structure to meet its own safeguarding obligations, integrate the EMI's API or SWIFT connectivity into its settlement system and establish the reconciliation process its institutional clients will audit. In a multi-entity structure – common for institutional VASPs – each entity may require a separate account, triggering a parallel EDD process for each.
What Are the Common Mistakes That Derail VASP EMI Onboarding?
The single most common mistake is applying to the wrong EMI. VASPs frequently approach high-street-adjacent payment institutions that have no VASP onboarding capability and no appetite to develop one, receive a declination framed as a risk decision, and then find that the declination itself requires explanation in subsequent applications. The market for EMI services to institutional VASPs is narrower than the total market for EMI services, and the selection process must reflect that narrowing.
The second most common mistake is submitting an incomplete or inconsistent legal pack. An EMI's compliance team will cross-check the VASP's regulatory authorisation against the public register of the home regulator, the corporate structure against Companies House or its equivalent, and the AML policy against the VASP's published terms of service. Inconsistencies – an entity name that differs between documents, an AML policy that does not address the VASP's actual product set, a beneficial ownership disclosure that does not match the cap table – generate requests for information that extend the timeline and signal internal disorganisation.
The third mistake is structural: applying for a single-entity EMI account when the business model requires a multi-entity structure. A VASP that holds custody, runs exchange and processes payments through a single legal entity will, at some point, face an EMI or regulator that requires separation. Building the structure after a relationship is established is harder than building it before. In our practice, we regularly advise on the entity architecture before the first EMI application is submitted – identifying the lines along which the regulator or the EMI will expect separation and building them into the initial structure.
A fourth mistake is underestimating the cross-border layer. An institutional VASP with clients in the EU, the UAE and Singapore may require EMI relationships in multiple jurisdictions – each with its own regulatory basis, its own safeguarding regime and its own AML documentation standard. A single offshore EMI account does not, in practice, serve all of those clients. The EU institutional counterparty will require a SEPA-capable account at a supervised EU payment institution. The UAE counterparty may require a locally supervised account. Treating these as a single account problem produces a single-point failure when one relationship closes.
How Should a Cross-Border Institutional VASP Structure Its EMI Relationships?
A cross-border institutional VASP should treat its EMI relationships as a stack, not a single account – with each layer mapped to a specific regulatory perimeter, a specific currency and a specific institutional counterparty category.
The EU layer typically runs through a CASP-authorised entity in a passporting-capable member state, with a payment account at an EMI that is itself authorised under the applicable electronic money directive and can pass SEPA credit transfers and receive SEPA direct debits. Under MiCA, the CASP authorisation does not carry payment-institution permissions; the CASP entity and the EMI are separate regulated entities, which means the relationship is a commercial B2B account relationship rather than an intra-group arrangement. Institutional EU counterparties expect this structure and will request the EMI's own regulatory credentials as part of counterparty due diligence.
The UAE layer is more complex. VARA's activity-based regime does not directly supervise payment accounts; the Central Bank of the UAE supervises payment-service providers operating in the UAE. A VARA-licensed exchange that needs to receive AED settlements from UAE institutional clients must work through a UAE-licensed payment service provider – which may be a licensed bank, a payment institution or a licensed exchange that also holds payment permissions. ADGM, as a financial free zone, adds a further jurisdictional layer: an FSRA-regulated entity in ADGM operates under a different legal regime from a VARA-licensed entity in mainland Dubai, and their respective payment relationships may not be fungible.
The Singapore layer, under the MAS Payment Services Act, is more integrated: MAS supervises both DPT service providers and payment institutions, and the regulatory expectations for safeguarding and AML are set by the same supervisor. That integration makes the compliance conversation with an EMI counterparty more predictable, but it does not reduce the documentation requirement.
In our cross-border practice, we map the full payment stack – operating entity, custody entity and payment layer – before advising on which EMI relationships to pursue. The map drives the application strategy. Without it, the VASP is applying in the dark.
If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Write to OBOLUS at info@oboluslaw.com to discuss your situation.
Decision Matrix: Which VASP Profile Needs Which EMI Structure?
Different institutional VASP profiles require materially different EMI structures. The following analysis maps four common profiles to their corresponding EMI architecture, indicative process complexity and key risk.
Profile A – Single-jurisdiction VASP, institutional client base concentrated in one hub. This profile – a MiCA-authorised CASP serving EU-based funds and family offices – can typically be served by a single EU EMI relationship, provided the VASP's own licence is in a passportable member state and the EMI has VASP onboarding experience. Process complexity is moderate; the main risk is EMI selection (many EU EMIs have not yet built VASP-specific onboarding workflows under the MiCA transition). Indicative timeline: a matter of weeks to a few months, depending on the EMI's queue.
Profile B – Dual-hub VASP, operating in UAE and EU with institutional clients in both. This profile requires at minimum two EMI relationships: one at a UAE-supervised payment institution for AED settlement and one at an EU EMI for EUR/SEPA flows. The corporate structure must be clear about which entity holds which licence and which account. The main risk is structural inconsistency – an EU EMI applying EU AML standards to a UAE-domiciled entity will require additional documentation of the UAE regulatory perimeter. Complexity is high; timeline extends accordingly.
Profile C – Global institutional exchange, multiple custody and trading entities. This profile typically requires a purpose-built payment architecture: separate EMI relationships for each major currency, entity-level accounts for each regulated subsidiary and a group-level treasury function that aggregates settlement across entities. The FATF jurisdiction exposure of each entity must be mapped and mitigated before application. Complexity is very high; the onboarding process is effectively a mini-project. Counsel involvement from the structuring stage – not the application stage – is essential.
Profile D – VASP in transition – existing EMI relationship at risk. A VASP that is mid-licence transition (for example, moving from an EU national VASP registration to a MiCA CASP authorisation) may find that its existing EMI relationship is contingent on the legacy registration and does not automatically carry over to the new authorisation. This risk is underappreciated. In our practice, we have seen VASP operators complete a licence transition in good faith, then discover that their EMI's compliance team requires a fresh onboarding process under the new regulatory status. Managing this risk requires advance communication with the EMI and, often, parallel account applications.
A Common Assumption About Offshore Licences and Global Access
A common assumption among institutional VASP operators is that a single offshore licence – held by an entity in a well-regarded offshore centre – is sufficient to open EMI relationships across the major hubs and serve institutional clients globally. This assumption does not survive contact with the market.
An offshore VASP registration may satisfy the VASP's home regulator. It does not satisfy an EU EMI applying MiCA-aligned AML standards, a UK EMI applying FCA registration requirements or a Singapore payment institution applying MAS expectations. Each of those EMIs is supervised by its own regulator and is accountable for the AML risk of its client base. An offshore licence from a jurisdiction that the relevant regulator does not regard as equivalent creates a documentation burden – often an insurmountable one – in the application process.
The practical implication is that institutional VASPs targeting clients in multiple major hubs generally require regulatory presence in each hub, or in hubs whose licences are recognised as equivalent by the target EMIs. A CASP authorisation in a passporting EU member state addresses the EU layer. A VARA licence addresses Dubai. A MAS DPT licence addresses Singapore. None of them addresses the others by itself. Designing the stack correctly, before committing capital to the first licence application, is the most consequential legal decision an institutional VASP makes in its early life.
Operators we advise routinely discover, during a pre-application mapping exercise, that their initial jurisdiction plan addresses one layer of the stack and leaves two others unresolved. Catching that early is the difference between a structured build and a reactive remediation.
Micro-Matter: EMI Account Recovery After Derisking
In a recent matter, a custodian operating under a dual-hub structure – licensed in an EU member state and in a Gulf free zone – found that its primary EMI closed its account during a routine portfolio review, citing the custodian's exposure to institutional clients in a third jurisdiction that the EMI had internally classified as elevated risk. The custodian's settlement flows stopped within days. We were engaged to map the structural reason for the closure, identify which element of the VASP's profile had triggered the EMI's risk model and develop a remediation plan. We identified that the issue was not the VASP's licence or its compliance programme but the jurisdictional classification of a subset of its client base. We structured a response that segregated those flows into a purpose-built sub-entity and prepared a fresh application pack for an alternative EMI with experience in that client segment. The account was re-established within the same quarter, and the custodian's settlement capability was restored before any institutional client relationship was materially affected.
Related at OBOLUS
- Banking, Payments & EMI Onboarding for Digital-Asset Businesses – the full practice overview covering all digital-asset banking and payment structures
- PSP and Acquiring Agreement in Abu Dhabi Global Market (ADGM) – payment structures under the FSRA regime in the ADGM free zone
- UAE (VARA/Dubai) vs. United Kingdom: Where to License a Crypto Business – comparative analysis for VASPs choosing between the UAE and UK regulatory perimeters
FAQ
Why do banks close crypto company accounts?
Banks and EMIs close VASP accounts primarily for risk-management reasons: the VASP's business model creates AML exposure the institution cannot adequately supervise with its current compliance infrastructure, the VASP's jurisdiction of licence is outside the institution's approved counterparty list, or a portfolio-level review determines that the aggregate crypto-sector exposure exceeds an internal limit. The closure decision is rarely about the individual VASP's conduct. It reflects the institution's risk appetite and its regulator's expectations. Remediation usually requires either a structural change – separating entities or adjusting the client-base profile – or a move to an EMI that has purpose-built its onboarding workflow for VASPs.
How can a VASP onboard with an EMI?
A VASP seeking EMI onboarding should begin with a readiness assessment: confirming that the regulatory licence is current, that the AML/KYC policy suite addresses the VASP's actual product set, that Travel Rule compliance is documented and that the corporate structure is clean and consistent across all regulatory registers. With that foundation in place, the VASP identifies EMIs with demonstrated VASP-sector experience and the currency and clearing capability the business requires, then submits a complete application pack. Enhanced due diligence – including a compliance-to-compliance call and review of audited financials – follows. Timeline varies by EMI and jurisdiction; specialist VASPs working with counsel routinely shorten this process materially by avoiding the most common documentation errors.
What does client-money safeguarding require?
Client-money safeguarding, as required under most EU and UK payment-regulation regimes, obliges an EMI or payment institution to hold client funds separate from its own funds, in a qualifying credit institution or in qualifying liquid assets, and to maintain a reconciliation process sufficient to identify each client's balance at any time. For a VASP that is not itself an EMI but holds fiat on behalf of institutional clients pending settlement, the safeguarding obligation flows through its EMI counterparty. The VASP's contractual arrangements with the EMI must reflect the safeguarding structure, and the VASP's own institutional clients will typically require contractual confirmation that their fiat balances are covered by the safeguarding regime.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – so that the structure your institutional clients require is built in from day one, not retrofitted after the first EMI declination. We advise crypto exchanges, custodians, token issuers and funds across more than seventy licensing jurisdictions. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP regulatory perimeters, EMI onboarding structures and cross-border payment compliance for institutional digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.