For a virtual asset service provider (VASP) – an exchange, custodian, broker or stablecoin issuer – the gap between a clean licence and an operational business is often a single word: banking. Regulated entities routinely secure their VASP authorisation, satisfy the regulator and then discover that every electronic money institution (EMI) in the region has declined to onboard them. The licence sits on the shelf. The fiat rails never open.
EMI onboarding for VASPs is a distinct legal and commercial process. It sits at the intersection of the applicable VASP regime, the EMI's own regulatory obligations under the relevant payment-services framework, and the AML/CFT expectations of the onboarding institution's home supervisor. A VASP that treats the bank or EMI relationship as an afterthought – something to sort out after licensing – compounds its own risk. In our practice, the businesses that move fastest are those that run the banking workstream in parallel with the licence application, not after it.
This page sets out how the onboarding process works, where it fails and how a regulated entity can improve its position materially before the first conversation with a prospective payment partner.
Why EMI Onboarding Fails for VASPs – and Why It Matters Now
The most common outcome of a poorly prepared EMI application is not a formal rejection. It is silence. The VASP submits, the EMI's compliance team reviews, and the application simply stops moving. Understanding why requires understanding what the EMI is actually evaluating.
An EMI operating under the applicable payment-services directive or its local equivalent carries its own licensing obligations. Its regulator – which may be the FCA, the Bank of Lithuania, the MFSA, or another national competent authority – expects it to manage the money-laundering risk of its client portfolio. A VASP client is, by category, a higher-risk customer. The EMI must conduct enhanced due diligence, satisfy itself on the VASP's own AML/KYC programme, and in many cases obtain sign-off from its own compliance committee before onboarding proceeds.
That is the structure. The failure points are practical. VASPs typically submit documentation designed for their regulator, not for a commercial counterparty's compliance department. The AML policy is written to satisfy the licensing authority; it does not explain, in terms an EMI underwriter can immediately verify, how the VASP screens customers, what it does when a transaction flag fires, or how it handles the Travel Rule (the obligation to pass originator and beneficiary data alongside a transfer).
A second failure point is entity structure. Where the VASP operates through a group – a holding entity in one jurisdiction, an operating entity in another, and a custody vehicle in a third – the EMI sees complexity without explanation. Unless the structure is presented as a coherent, documented rationale, it reads as obfuscation. In our practice, we have seen well-licensed groups lose six months of runway because the onboarding pack did not address the cross-border structure at all.
The regulatory environment is not easing. Supervisors across the EU, the UK and the major offshore centres have, in recent years, increased their expectations of EMIs regarding high-risk customer categories. That pressure flows directly through to VASP applicants.
Operating without a functioning fiat channel exposes the business to operational paralysis – not just inconvenience. Payroll, vendor payments, client withdrawals and regulatory capital deposits all require a live account. The enforcement risk of operating without proper payment infrastructure is secondary; the primary risk is that the business simply cannot function.
For a scoped assessment of your entity's banking readiness, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base, the transaction profile – change the analysis before the first outreach to an EMI.
The Regulated Basis: What an EMI Is and What It Requires of a VASP Client
An EMI holds authorisation to issue electronic money and provide payment services under the applicable regime in its home jurisdiction. In the EU, that framework is the second Payment Services Directive and the Electronic Money Directive, now subject to ongoing revision; in the UK, the corresponding MLR-registered or FCA-authorised status applies. The EMI is not a bank. It cannot provide credit. But it can hold client money in safeguarded accounts and execute payment transactions – which is precisely what a VASP needs for fiat settlement.
Because an EMI safeguards client funds, its regulator expects rigorous due diligence on the source of those funds. A VASP customer introduces layered risk: the VASP's own customers deposit fiat or convert crypto, and those underlying flows may be difficult for the EMI to trace. The EMI's compliance obligation extends to the VASP's customer base, at least at a programme level – meaning the EMI must satisfy itself that the VASP's AML controls are adequate before it agrees to process transactions on the VASP's behalf.
The practical consequence is that an EMI onboarding review of a VASP looks quite different from onboarding a standard business customer. The EMI will typically request the VASP's full AML/KYC policy, its risk appetite statement, evidence of its own regulatory authorisation, details of its transaction monitoring system, the identity of its beneficial owners and, increasingly, its Travel Rule compliance solution. Where the VASP operates in multiple jurisdictions, the EMI will want to understand which entity is the contractual counterparty and how flows between group entities are managed.
This is not arbitrary friction. The EMI is managing its own regulatory exposure. Businesses that understand this – and prepare documentation that speaks directly to the EMI's compliance department rather than to a licensing authority – onboard materially faster. Those that do not frequently end up in the silence described above.
How Does the EMI Onboarding Process Work for a Regulated VASP?
The onboarding process for a regulated VASP with a prospective EMI partner moves through several identifiable stages, each with its own documentation requirements and decision points.
The first stage is pre-qualification. Most EMIs that accept VASP clients have, whether formally or informally, a pre-screening process. This may be a short questionnaire or an introductory call. The purpose is to determine whether the VASP's profile falls within the EMI's risk appetite at all. At this stage, the VASP should be prepared to state its jurisdiction of authorisation, its licence category, its primary revenue model, the geographic scope of its user base, and its approximate monthly fiat throughput. A VASP that cannot answer these questions cleanly is unlikely to proceed.
The second stage is formal due diligence. Here the VASP submits a full compliance pack. The core components are: certified copy of the VASP licence; corporate structure chart with beneficial ownership detail to the natural-person level; AML/KYC policy (current, dated and signed by the MLRO); Travel Rule compliance statement; transaction monitoring system description; sample customer risk assessment; and, where applicable, the VASP's own audited financial statements. Some EMIs also request a third-party AML audit report.
The third stage is the EMI's internal credit and compliance review. This is the stage most opaque to the VASP. The file moves through the EMI's compliance committee, sometimes its board. Timelines vary by institution and by the complexity of the VASP's structure. We advise clients to treat this stage as active, not passive – maintaining responsive communication with the EMI's relationship team and being prepared to answer supplemental questions promptly, because delay in responding is frequently read as an inability to respond.
The fourth stage is commercial terms and account setup. If the compliance review concludes positively, the EMI issues a terms proposal covering pricing, transaction limits, reporting obligations and the circumstances under which the account may be suspended or terminated. These terms require careful legal review. Termination clauses and suspension rights in EMI agreements are often drafted broadly, and a VASP that accepts standard terms without negotiation may find its account frozen on a standard compliance review months later.
The final stage is integration and testing. For VASPs that require API-level connectivity – to support automated fiat settlement, batch withdrawals or real-time balance reporting – this stage involves technical work alongside the legal relationship. Ensuring that the integration agreement, the data-sharing terms and the liability allocation are consistent with the master account agreement is a step that is often skipped and later regretted.
What Documentation Does an EMI Actually Want?
The compliance pack that secures an EMI relationship is not the same document set that secured the VASP licence. The two audiences have different questions. The licensing authority asks whether the business meets the regulatory threshold for authorisation. The EMI's compliance team asks whether the VASP's ongoing operations present manageable risk to the EMI's own regulatory standing.
In our practice, we prepare VASP compliance packs that address both audiences simultaneously – because the best-prepared businesses are those that have structured their compliance documentation from the outset to serve both purposes. The key documents, and the specific things each one must demonstrate to an EMI underwriter, are as follows.
The AML/KYC policy must be current and operational, not a template. It should describe the customer risk-rating methodology, the enhanced due diligence triggers, the escalation path for suspicious activity, and the name and contact details of the current MLRO. A policy dated two years ago and obviously not updated since the VASP's user base grew is a compliance red flag.
The corporate structure chart must show every entity in the group, the jurisdiction of each, the percentage ownership at each level, and the identity of every natural person who directly or indirectly holds more than a defined threshold interest. Many EMIs apply a lower threshold than the standard beneficial ownership definition used for general corporate purposes. Where ownership is through a trust or fund structure, the trustee or general partner details are required at minimum.
The Travel Rule compliance statement is increasingly non-negotiable. The FATF Recommendation 15 standard on virtual asset transfers requires originator and beneficiary data to accompany transfers above the applicable threshold, and EMIs in FATF-member jurisdictions are required to satisfy themselves that their VASP customers have a compliant Travel Rule solution in place. This means naming the solution, describing the message standard used, and confirming which counterparty jurisdictions are covered.
Financial statements – or, for newer VASPs, a detailed business plan with realistic transaction projections – allow the EMI to assess the fiat throughput it would be processing and to calibrate its own operational capacity and risk exposure. Projections that are obviously aspirational rather than grounded in existing user data tend to reduce confidence rather than increase it.
Cross-Border Structures and the Multi-Jurisdiction Problem
A VASP serving users across multiple jurisdictions rarely operates from a single entity. The typical structure – holding company in a tax-efficient domicile, operating VASP licence in an EU or UK-regulated hub, custody held separately, and perhaps a secondary licence in a growth market such as the AIFC or Singapore – creates a documentation challenge that an unprepared compliance pack fails to resolve.
The EMI's central question for a multi-entity group is: which entity is the account holder, and who controls the flows? Where the answer requires the EMI to trace ownership through three layers across as many jurisdictions, the compliance reviewer's instinctive response is to flag the structure for escalation. Escalation means delay. Delay, in a VASP's early months, means operational risk.
The solution is not to simplify the structure for the EMI's benefit – restructuring to satisfy a banking counterparty rarely makes sense from a tax or regulatory perspective. The solution is to present the structure with a clear, written rationale. Each entity's purpose should be explained. The flow of funds between entities should be mapped. The regulatory basis for each entity's activities should be stated. Where the holding structure involves a jurisdiction not known to the EMI's compliance team – the AIFC, the ADGM, or the BVI FSC regime, for example – a one-page jurisdictional brief covering the regulatory framework and the VASP's authorised activities in that jurisdiction is often the difference between a smooth review and a prolonged one.
The cross-border element also affects which EMI is the right target. A VASP with a MiCA CASP authorisation passporting across the EU will find more receptive EMIs in the EU payment space than a non-EU VASP seeking to process EUR transactions. Similarly, a VASP with an FCA-registered status will have a different counterparty universe for GBP rails than for EUR. Mapping the right EMI targets by currency, geography and risk appetite – before the outreach begins – avoids wasted applications and reputational cost within a small market.
In a recent cross-border matter, a custodian with licences in two jurisdictions had been declined by three EMIs without explanation. We reviewed the compliance pack, identified that the corporate structure had never been presented with a written rationale, and that the AML policy referenced the licensing jurisdiction's requirements but said nothing about the second jurisdiction's regime. We restructured the pack, added the jurisdictional briefs and a Travel Rule implementation note. The custodian onboarded with an EU EMI within a matter of weeks of resubmission.
Common Mistakes VASPs Make in the EMI Application
The most expensive mistake is timing. Treating the EMI relationship as post-licensing means the business has already burned runway on entity setup, licence fees and staffing before discovering that its banking options are limited. The EMI outreach should begin during the licensing process, not after it. Many EMIs will conduct a preliminary review – sometimes informally – while the VASP licence application is in progress, allowing the business to identify documentation gaps before the full onboarding submission.
The second common mistake is targeting the wrong EMIs. Not every EMI that advertises VASP onboarding is operationally equipped to handle it. Some have risk appetites that exclude exchanges; others will onboard custodians but not brokers; a few specialise in specific currency corridors. Approaching the broadest possible set of EMIs simultaneously is not a strategy. It produces multiple simultaneous due diligence requests, inconsistent information across submissions and – if any EMI shares adverse information with its network – reputational damage that is difficult to reverse.
The third mistake is under-resourcing the MLRO function at the time of onboarding. An EMI's compliance team will frequently ask to speak directly with the VASP's MLRO. A VASP whose MLRO is part-time, unavailable or clearly inexperienced with the specific compliance question being asked will not onboard successfully. The MLRO is not a compliance box to tick; the MLRO is the face of the VASP's AML programme to every banking counterparty.
A common assumption among first-time VASP operators is that a single offshore licence – the Cayman VASP Act registration or a BVI FSC registration, for example – is sufficient to open EMI accounts across Europe and the UK. It is not. EU and UK EMIs operate under regulatory frameworks that require them to assess whether their VASP clients are themselves subject to adequate AML supervision. A registration in a jurisdiction not on the FATF grey list but also not an EU/EEA or UK regulated regime will trigger enhanced scrutiny or outright decline. The VASP's licence must be in a jurisdiction the EMI's regulator recognises as having an equivalent AML standard.
If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. To map the licence, banking and compliance stack for your build, write to info@oboluslaw.com.
Decision Matrix: Which EMI Profile Suits Which VASP?
No single EMI solution fits every VASP profile. The right counterparty depends on the VASP's licence jurisdiction, its transaction volume, the currencies it needs to settle and the complexity of its client base. The following matrix describes four common operator profiles and the appropriate approach for each.
A newly licensed EU CASP operating under MiCA, with a small user base and primarily EUR settlement needs, is best positioned to approach EMIs licensed in the same member state or in an adjacent EU jurisdiction with a track record of VASP onboarding. The shared regulatory framework reduces the compliance delta. The VASP should lead with its CASP authorisation confirmation, its AML policy and a realistic transaction projection. Timeline to onboarding, assuming documentation is in order, is typically a matter of weeks to a few months.
A mid-size exchange with a MiCA passport and multi-currency settlement requirements – EUR, GBP, USD, potentially CHF – needs a different approach. Here, a single EMI relationship is rarely sufficient. The VASP should map its currency requirements and identify at least two or three EMI partners, potentially including an FCA-authorised EMI for GBP rails and a US-licensed money services business for USD. This is a programme, not a single application. Legal review of the interplay between the agreements is essential to avoid conflicting obligations.
A crypto custodian holding assets on behalf of institutional clients has a different risk profile from an exchange: lower transaction frequency, higher average balances, and a client base that is itself regulated. This profile is generally more attractive to risk-conservative EMIs. The custodian should present its safeguarding arrangements, its institutional client onboarding procedures and, if applicable, its insurance arrangements. Timelines tend to be shorter where the client base is demonstrably institutional.
A VASP licensed in a non-EU offshore jurisdiction – the BVI, Cayman or the AIFC – and seeking EU or UK fiat rails faces the highest compliance threshold. Here the VASP must address, proactively, the equivalence question: does the licensing jurisdiction meet an equivalent AML/CFT standard to the EMI's own regulatory framework? Where it does not, the VASP may need to establish a secondary regulated entity in an EU or UK-adjacent jurisdiction before EMI onboarding becomes realistic. We map this licence stack before the client commits capital to a structure that cannot be banked.
Self-Assessment Checklist Before You Apply
The following steps allow a VASP to assess its readiness before making the first formal approach to an EMI. None of them constitute legal advice on a specific situation, but each one reflects a gap we have seen close an application.
First, confirm that the VASP licence is unconditional. A provisional or conditional authorisation – one that imposes conditions on the volume of transactions, the customer categories or the jurisdictions served – may not satisfy an EMI's onboarding requirement. The licence document should be reviewed for any such conditions before it is presented to a prospective EMI partner.
Second, verify that the AML/KYC policy is current, complete and operationally accurate. It should reflect the VASP's actual current procedures, not the procedures described in the original licence application. If the VASP's transaction monitoring system has changed, if the MLRO has changed, or if the customer base has expanded materially since the policy was last updated, the policy must be refreshed.
Third, document the corporate structure in a form that a non-specialist compliance reviewer can follow in under five minutes. The chart must go to natural persons. Every entity must show its jurisdiction of incorporation and its regulatory status.
Fourth, confirm the Travel Rule solution. Name the provider, describe the standard used and list the jurisdictions covered. Where coverage is incomplete – as it frequently is for smaller VASPs – explain the compensating controls applied for transfers to and from uncovered counterparties.
Fifth, identify the target EMI universe by currency and risk appetite before making any approach. Research each target's publicly stated VASP policy, if any. Prioritise EMIs with a documented track record in the VASP category. Limit the first round of applications to two or three well-researched targets rather than a broad sweep.
Sixth, prepare for the MLRO conversation. The EMI's compliance team will ask questions that the MLRO must answer with confidence and specificity. A pre-meeting internal review of likely questions – covering sanctions screening, PEP procedures, suspicious transaction reporting and Travel Rule implementation – materially improves the quality of that conversation.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital Asset Businesses – the practice-area overview covering fiat rails, payment licensing and account access strategies across jurisdictions.
- EMI Onboarding for VASPs: A Cross-Border Perspective – how multi-jurisdiction VASP structures affect banking access and which configurations open the most EMI options.
- Regulator and AML Audit Defence in the Czech Republic – managing supervisory scrutiny and AML audit processes in a MiCA-transition EU jurisdiction.
FAQ
Why do banks close crypto company accounts?
Banks and EMIs close VASP accounts primarily because the VASP's compliance documentation fails to address the onboarding institution's own regulatory exposure. Common triggers include inadequate AML policies, undisclosed changes in business model or customer base, Travel Rule non-compliance, adverse transaction monitoring outputs and, in some cases, regulatory pressure from the institution's own supervisor on its VASP client portfolio. A well-documented AML programme and proactive communication with the account provider significantly reduce the risk of closure.
How can a VASP onboard with an EMI?
A VASP onboards with an EMI by presenting a compliance pack that addresses the EMI's regulatory obligations as well as the VASP's own. The pack should include the unconditional VASP licence, a current AML/KYC policy, a Travel Rule compliance statement, a full corporate structure chart with beneficial ownership detail, and financial projections or audited statements. The process moves through pre-qualification, formal due diligence and internal compliance committee review before commercial terms are agreed. Preparation and responsive communication throughout materially reduce the timeline.
What does client-money safeguarding require?
Client-money safeguarding under the applicable payment-services regime requires an EMI to hold customer funds in accounts that are segregated from the institution's own assets and protected in the event of the EMI's insolvency. For a VASP using an EMI for fiat settlement, this means the VASP's client fiat balances are held in a safeguarded pool rather than commingled with the EMI's operating funds. The specific mechanics – whether by segregated account, insurance or a guarantee instrument – vary by jurisdiction and by the EMI's regulatory status.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, banking and payment stack across operating, custody and payment layers before you commit to a structure – so the rails open when the licence does. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when the situation demands it. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP authorisation, AML programme design and EMI onboarding strategy for regulated digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.