For a virtual asset service provider (VASP) – a crypto exchange, custodian, token issuer or funds platform – the absence of reliable fiat rails is an existential risk. Regulators can grant a licence; no regulator can compel a bank or electronic money institution (EMI) to open an account. That asymmetry is the defining commercial problem in cross-border digital-asset practice, and it is the one OBOLUS is most frequently engaged to solve. This page sets out the regulated basis for VASP banking relationships, the practical onboarding process across the leading EMI jurisdictions, the mistakes that stall or kill applications, and how the cross-border reality – where the VASP entity sits, where its users transact, where its custodian banks – reshapes every step of the analysis.
The Fiat Rail Problem: Why VASPs Lose Banking
Banks and EMIs close or refuse crypto company accounts for reasons that are structural, not arbitrary. The core concern is de-risking – the practice by which a financial institution exits an entire customer category rather than manage the compliance cost of individual relationships. VASPs sit in a category that carries above-average AML/CFT scrutiny under the FATF Recommendations, including Recommendation 15, which brought virtual-asset businesses within the scope of global anti-money laundering standards. A bank that cannot perform adequate customer due diligence on a VASP's underlying client base, transaction flows and source of funds will typically choose not to bank the VASP at all.
The problem compounds across borders. A VASP licensed in Lithuania under the Bank of Lithuania's CASP regime – transitioning to full MiCA authorisation – may find that its EU licence carries weight with certain EMIs but not with correspondent banks in the United States, where FinCEN's VASP guidance and state money-transmitter licensing expectations govern separately. A VASP incorporated in the BVI under the VASP Act 2022 and licensed by the BVI Financial Services Commission may face account closures in the EU because its home jurisdiction does not trigger the mutual recognition that a MiCA-authorised operator enjoys through EU passporting.
In our cross-border practice, the single most common cause of failed EMI onboarding is not the VASP's compliance posture but its structural presentation: the entity structure, the jurisdiction of licensing and the documentation package do not cohere into a picture the EMI's compliance team can approve. The answer is not a better cover letter. It is a correctly built structure presented with precision.
Under the FATF framework, VASPs are subject to the same customer due diligence, transaction monitoring and Travel Rule obligations – the requirement to pass originator and beneficiary data with qualifying virtual-asset transfers – that apply to traditional financial institutions. EMIs onboarding VASPs are themselves subject to those standards and will assess the VASP accordingly.
The process above describes the structural baseline. Your facts – the entity, the user base, the banking geography – change the analysis materially. For a scoped assessment of your fiat-rail situation, contact OBOLUS at info@oboluslaw.com or map your options here.
What Is the Regulated Basis for VASP-EMI Relationships?
An EMI – authorised under the applicable e-money regime in its home jurisdiction – may hold and transfer fiat funds on behalf of business clients, including VASPs. In the EU, the relevant regime sits under MiCA's broader financial-services environment alongside the e-money directive framework administered by national competent authorities; ESMA provides coordination but individual-state regulators issue the authorisations. An EMI passported across the EU can serve a MiCA-authorised CASP as a regulated counterpart without needing separate bilateral arrangements in each member state.
The relationship is bilateral and regulated on both sides. The VASP must satisfy the EMI that it is itself supervised – either as a licensed CASP under MiCA, under a national VASP regime such as the FCA's cryptoasset registration in the UK, or under a comparable framework in its home jurisdiction. The EMI must satisfy its own regulator that its VASP client population is adequately managed as a compliance risk. That means the EMI will conduct enhanced due diligence on the VASP: corporate structure, beneficial ownership, AML/CFT programme, Travel Rule compliance capability, user base demographics and the jurisdictions in which the VASP operates.
Where a VASP operates in multiple jurisdictions – as most commercially significant operators do – the EMI must assess not just the home-state licence but the full operating footprint. A VASP licensed by VARA in Dubai but actively serving users in the EU without a MiCA CASP authorisation, or serving US retail users without the appropriate state money-transmitter licensing, presents a compliance risk that most EMIs will decline. Regulatory perimeter gaps in the VASP's own structure are the leading cause of EMI rejection.
Which EMI Jurisdictions Matter for Crypto Businesses?
The choice of EMI jurisdiction is a strategic decision that interacts with the VASP's licensing stack, its banking geography and its user-base. The EU is the largest pool of regulated EMI capacity for digital-asset businesses. EMIs regulated in Lithuania, Malta and other EU member states with active fintech sectors have historically shown greater appetite for VASP clients than larger retail banks, partly because their compliance frameworks are scaled to assess fintech risk rather than traditional banking risk. Under MiCA, a VASP holding a CASP authorisation in any EU member state can passport that authorisation across the bloc; the EMI relationship benefits from the same passporting logic on the other side.
Outside the EU, the UK FCA's e-money institution regime and the associated cryptoasset registration framework under the Money Laundering Regulations create a parallel EMI pool. UK-regulated EMIs have developed significant VASP-onboarding capability, though the FCA's own financial-promotion rules for crypto marketing create compliance requirements that flow through to the VASP's relationship with its UK EMI. In the Gulf, VARA-licensed operators in Dubai and FSRA-regulated entities within ADGM in Abu Dhabi interact with EMIs and payment institutions operating within those free zones, creating a more contained but increasingly capable set of fiat-rail options in the region.
Singapore's MAS-regulated Payment Services Act framework, which licenses Digital Payment Token service providers, creates a further EMI pool in Asia. SFC-licensed virtual-asset trading platforms in Hong Kong interact with Hong Kong-authorised banks and payment institutions. In our practice, operators expanding across time zones – EU entity, Gulf entity, Asia-Pacific entity – require a coordinated banking strategy rather than three parallel and uncoordinated applications. The jurisdictions interact: a bank in Singapore may ask about the EU entity's CASP status; an EU EMI may ask about the VARA licence's scope.
How Does the EMI Onboarding Process Work for a VASP?
EMI onboarding for a VASP follows a structured due-diligence sequence that differs from standard corporate account opening in both depth and documentation expectation. The process typically begins with a pre-screening call or questionnaire in which the EMI's compliance team assesses the VASP's licence, jurisdictional footprint, user-base profile and transaction-volume expectations. This pre-screening is not a formality. Many rejections occur here, before a formal application is submitted, because the VASP's materials do not present a coherent regulatory picture.
Assuming pre-screening is passed, the formal application requires a comprehensive compliance package. The core elements are: the VASP's corporate structure chart (showing all entities, their jurisdictions of incorporation, their regulatory status and the ultimate beneficial owners), the AML/CFT policy and procedure documentation, the Travel Rule compliance solution and evidence of its deployment, a source-of-funds explanation for the VASP's own capital and for expected client flows, and the VASP's own customer risk-rating methodology. The EMI will also require details of the VASP's own banking relationships – existing and prior – and may request references from those institutions.
The timeline from formal application to account activation varies by EMI, by jurisdiction and by the complexity of the VASP's structure. In our experience advising operators across this process, simpler structures with a single operating entity in a well-regarded licensing jurisdiction resolve faster than multi-entity structures spanning several jurisdictions. Operators that present a clean, complete documentation package at the outset consistently experience shorter review periods than those who respond to information requests reactively.
A micro-matter from our recent practice illustrates the dynamic: a custodian with entities in two EU jurisdictions and one Gulf jurisdiction had its initial EMI application declined after a six-week review. The stated reason was inadequate Travel Rule documentation. We reviewed the application and identified that the issue was not the Travel Rule solution itself – which was technically compliant – but the failure to demonstrate that the solution operated consistently across all three entity-level operations. We restructured the compliance presentation to show the integrated policy at group level, resubmitted, and the application was approved within a matter of weeks. The substance had not changed; the presentation had.
What Are the Most Common Mistakes in VASP EMI Onboarding?
The most consequential mistake VASPs make in EMI onboarding is applying without resolving the structural question first. An EMI application is a snapshot of the applicant's structure at a point in time. If the structure contains a jurisdictional gap – an entity operating in a market where it is not licensed, a beneficial-ownership chain that is opaque, a missing Travel Rule solution – the EMI will identify it. Remedying the gap after rejection costs time that the VASP's commercial timeline cannot absorb. The correct sequence is: build the right structure, then apply.
The second common mistake is presenting the VASP's AML/CFT documentation as a compliance exercise rather than as a business explanation. EMI compliance teams are not regulators reviewing a licence application. They are assessing whether they can manage the risk of the relationship. Documentation that explains why the VASP's client-base risk is manageable – with reference to the VASP's own KYC standards, its transaction-monitoring thresholds, its jurisdictional exclusions and its escalation procedures – is more effective than documentation that simply recites regulatory requirements.
Third: failure to anticipate the EMI's correspondent-banking constraints. Many EMIs do not hold direct central-bank accounts; they rely on correspondent banks for USD and sometimes EUR clearing. Those correspondent banks apply their own de-risking logic to the EMI's client portfolio. A VASP client that raises correspondent-bank concerns – because of its jurisdiction of licensing, its user-base geography or its transaction-volume profile – will not be onboarded even if the EMI is willing, because the EMI's correspondent will constrain it. Understanding the correspondent-banking layer is a prerequisite for selecting the right EMI.
A common assumption in the market is that a single EMI relationship is sufficient for a VASP's fiat-rail needs. In our experience, this assumption creates a single point of failure that can halt a business overnight. Regulators closing, EMIs being acquired or changing risk appetite, correspondent banks withdrawing – all of these events have occurred in the digital-asset banking environment. A resilient fiat-rail structure has at minimum two EMI relationships, ideally in different jurisdictions, with clearly documented fallback procedures.
If a prior EMI application stalled or an account was closed, a second read of the structural facts can surface the reason and identify the route back. Write to OBOLUS at info@oboluslaw.com or map your options here.
How Does the Cross-Border Reality Change the Banking Stack?
A VASP operating across jurisdictions faces a banking problem that is qualitatively different from a domestic operator's. The legal entity that holds the EMI account, the entity that holds the regulatory licence, the entity that holds client assets and the entity that employs staff may all be in different jurisdictions for legitimate tax and structuring reasons. Each jurisdictional layer adds a compliance question that the EMI must answer: Is the entity making the application the entity that is regulated? Is the client money held at the entity level or at a group level? Does the licence in one jurisdiction authorise the activities being funded through the EMI account?
The interaction between a MiCA CASP authorisation and a VARA licence in Dubai is a practical illustration. A group with both authorisations may legitimately serve EU users through the CASP entity and Gulf users through the VARA entity. The EMI banking each entity must understand the intra-group flows – fees, treasury movements, intercompany loans – as well as the external client flows. An EMI compliance team that cannot trace those flows will treat the relationship as high-risk and either decline or impose restrictive transaction limits.
Tax and structuring choices further complicate the banking picture. A group that has structured its intellectual-property holding, its operating function and its treasury function in different jurisdictions – a common arrangement for tax efficiency – must explain that structure clearly to each EMI. The structure may be entirely legitimate; its complexity is a compliance-assessment risk if not explained proactively. In our cross-border practice, we regularly advise groups on aligning their tax and structuring rationale with their banking disclosure, so that the story the group presents to an EMI coheres with the story it presents to its auditors and to its regulators.
Allied counsel in the relevant jurisdiction play a material role in multi-entity structures. A group with entities in the EU, the Gulf and Singapore requires local counsel input on the regulatory perimeter in each jurisdiction – what the entity can do, who it can serve, and what the AML obligations are. We coordinate that input and present it to EMIs as an integrated group-level compliance picture, rather than leaving the EMI to piece together advice from three different legal traditions.
Which EMI Onboarding Profile Fits Your VASP?
The right EMI onboarding strategy depends on the VASP's regulatory status, its operating model and its user-base geography. Three broad profiles describe most operators we advise.
Profile A – Single-jurisdiction CASP under MiCA. A VASP with a single MiCA CASP authorisation in an EU member state and a user base predominantly in the EU is the cleanest onboarding profile. The regulatory story is coherent. The passporting mechanism means the VASP can serve users across the EU without additional per-state authorisation. The appropriate EMI is an EU-regulated institution with demonstrated VASP-client capability and, ideally, a correspondent-banking relationship that does not exclude digital-asset client flows. Timeline from a well-prepared application to active account: variable, but structurally simpler than multi-entity profiles.
Profile B – Multi-jurisdictional operator (EU + Gulf or EU + Asia-Pacific). A VASP with a MiCA CASP entity and a VARA-licensed Dubai entity, or a MiCA entity and an MAS-licensed Singapore entity, requires a coordinated banking strategy. The EU entity needs an EU EMI relationship; the Gulf or Asia-Pacific entity needs a regional banking solution. The intra-group flow documentation is the critical compliance challenge. Timeline and complexity are higher. The risk of a gap in the regulatory perimeter – an entity operating outside its licensed scope – is the leading cause of rejection in this profile and must be resolved before any application is submitted.
Profile C – Early-stage VASP without a primary licence. An operator without a primary regulatory licence seeking EMI services faces the hardest onboarding environment. Most regulated EMIs will not onboard an unlicensed VASP. The appropriate first step is to obtain the licence – through MiCA in the EU, the FCA registration in the UK, the VARA regime in Dubai or another recognised framework – before approaching EMIs. Attempting EMI onboarding before licensing is not only structurally likely to fail; it creates a compliance record that may make subsequent applications harder.
What Does Client-Money Safeguarding Require at the EMI Level?
Client-money safeguarding is a regulatory requirement that flows from the EMI's own authorisation and shapes how it holds fiat funds on behalf of the VASP's clients. Under the applicable e-money regimes in the EU and the UK, an EMI is required to safeguard funds received in exchange for electronic money – segregating them from the EMI's own funds and holding them in designated safeguarding accounts or in qualifying liquid assets. This requirement applies to the EMI; the VASP is responsible for ensuring that its contractual arrangements with the EMI comply with the VASP's own client-money obligations under its regulatory licence.
The interaction between the VASP's MiCA CASP obligations – which include client-asset safeguarding requirements for crypto assets – and the EMI's fiat safeguarding obligations creates a dual-layer safeguarding structure that operators must document explicitly. Regulators in the leading hubs increasingly expect VASPs to demonstrate that this dual-layer structure works in practice: that the VASP knows which entity holds client fiat, under what safeguarding mechanism, and what happens to those funds in the event of the EMI's insolvency. This is not a theoretical exercise; EMI insolvency events have occurred in the digital-asset sector.
In our practice, we advise VASPs to treat the safeguarding question as a contractual negotiation with the EMI, not as a compliance box to be ticked. The VASP agreement with the EMI should specify the safeguarding model, the account designation, the reporting frequency and the VASP's rights of access to safeguarded funds. Where those terms are absent or ambiguous, the VASP's clients bear the insolvency risk that the safeguarding regime was designed to eliminate.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital-Asset Businesses – the full practice overview for VASP fiat-rail strategy
- Payment Institution Licensing for Regulated Entities – how a payment institution licence changes the banking options for a VASP
- EMI Onboarding for VASPs: Institutional Clients – specific considerations when the VASP's client base is institutional
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because of de-risking – a practice by which a financial institution exits an entire customer category rather than manage the compliance cost of individual relationships. VASPs carry above-average AML/CFT scrutiny under the FATF framework. A bank that cannot adequately assess the VASP's underlying client flows, beneficial ownership, Travel Rule compliance and jurisdictional footprint will typically choose not to hold the relationship. The remedy is structural: a well-licensed, well-documented VASP presenting a coherent compliance picture reduces de-risking risk materially, but does not eliminate it. Banking appetite varies by institution and by region.
How can a VASP onboard with an EMI?
A VASP onboards with a regulated EMI through a structured due-diligence process. The core steps are: pre-screening against the EMI's VASP-client policy; submission of a comprehensive compliance package covering corporate structure, beneficial ownership, AML/CFT programme, Travel Rule solution and source of funds; a review period during which the EMI may issue information requests; and, if approved, account activation with agreed transaction limits and reporting obligations. The critical prerequisite is that the VASP holds a recognised regulatory authorisation – a MiCA CASP, an FCA cryptoasset registration, a VARA licence or an equivalent – before approaching an EMI. Unlicensed applicants are generally declined.
What does client-money safeguarding require?
Under the applicable e-money regimes, a regulated EMI must segregate client fiat funds from its own funds and hold them in designated safeguarding accounts or qualifying liquid assets. For a VASP using an EMI to hold client fiat, this creates a dual-layer safeguarding obligation: the EMI safeguards the fiat; the VASP safeguards the crypto assets under its own regulatory licence. The VASP should ensure its agreement with the EMI specifies the safeguarding model, account designation, reporting frequency and access rights, so that clients are protected in the event of the EMI's insolvency. Ambiguous contractual terms shift insolvency risk to the VASP's clients.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – and we regularly advise crypto exchanges, custodians, token issuers and funds on their banking and EMI strategy across more than seventy licensing jurisdictions. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Victor Olsen, Regulatory and Compliance Analyst – specialising in VASP licensing, EMI onboarding strategy and cross-border regulatory compliance for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.