EST · MMXXVI
Home/Services/Banking Payments Emi/EMI onboarding for vasps: Legal Counsel for Digital-Asset Firms
Banking, Payments & EMI Onboarding

EMI onboarding for vasps: Legal Counsel for Digital-Asset Firms

Emi onboarding for vasps: Legal Counsel for Digital-Asset Firms. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Ta

A virtual asset service provider (VASP) that has secured its licence often discovers that banking is the harder problem. Payment processors decline without explanation. EMI applications stall. Fiat rails that looked stable close overnight. The consequence is not merely inconvenience — it is an operational halt that can strand client funds, trigger regulatory scrutiny and, in the worst case, force an orderly wind-down. EMI onboarding for VASPs is the structured legal process of securing and maintaining access to fiat payment infrastructure in a way that satisfies both the payment institution and the regulator. In our practice, we treat that process as a distinct legal mandate, not an afterthought to licensing.

This page sets out what the process involves, where it fails, and how we advise businesses through it.

Why Fiat Access Is a Regulated Problem, Not a Commercial One

The relationship between a VASP and an electronic money institution (EMI) – a licensed payment firm that issues electronic money and holds client funds – is governed by overlapping regulatory regimes, not simply by contract. The EMI is itself supervised: under MiCA and the revised Payment Services Directive in the EU, under the FCA in the UK, under MAS in Singapore, and under equivalent regimes elsewhere. Each of those regimes imposes de-risking obligations – internal policies that lead payment institutions to decline or exit relationships with higher-risk categories of customer.

VASPs sit at the apex of that risk hierarchy for most compliance teams. The concern is not arbitrary. FATF Recommendation 15 requires financial institutions to apply risk-based AML measures to virtual-asset businesses they service, and supervisors in every major hub have made clear that the servicing institution shares in the compliance risk of its VASP client. An EMI that onboards a VASP without adequate due diligence faces its own regulatory exposure.

The practical consequence is that a VASP presenting itself to a payment institution as a generic business will be declined. The VASP must present itself as a regulated, AML-compliant, operationally coherent entity whose risk can be assessed, contained and priced. That is a legal positioning exercise, not a sales one.

The process above describes the standard path. Your facts — the entity, the user base, the banking — change the analysis. For a scoped assessment of your payment access situation, contact OBOLUS at info@oboluslaw.com.

What Regulatory Basis Governs the EMI Relationship?

An EMI operating under MiCA's predecessor and successor regimes, or under the FCA's authorisation regime, must satisfy its own supervisors that its VASP clients meet the standard of a regulated counterparty. That means the VASP must demonstrate: a current licence or registration in its home jurisdiction; a documented AML/KYC programme aligned to FATF standards; compliance with the Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer); and a governance structure that a compliance officer can map to a known regulatory category.

The jurisdictional origin of the VASP matters. A CASP authorised under MiCA in a EU member state carries passporting rights and a recognised supervisory baseline. A VASP licensed by VARA in Dubai, MAS in Singapore, or the SFC in Hong Kong operates under well-structured regimes that most European and UK EMIs can evaluate. A VASP registered in a jurisdiction with thinner supervision faces a harder path, even if the registration is technically valid.

This is the first structural point we address in any mandate: whether the client's existing licence, and the jurisdiction in which it sits, is legible to the target payment institution. If it is not, re-domiciliation or the addition of a second licence in a recognised hub may be the more direct route to payment access than repeated EMI applications from an unrecognised base.

How Does the EMI Onboarding Process Work in Practice?

EMI onboarding for a VASP proceeds in four structured phases. Each phase has a distinct legal dimension, and failure at any phase typically reflects a legal or documentation gap rather than a commercial one.

Phase 1 – Due Diligence Package Preparation. The EMI's compliance team will request a comprehensive customer due diligence package. For a VASP, this extends well beyond standard corporate documents. It includes the licence or registration certificate, the AML policy and procedure manual, the Travel Rule compliance methodology, the key management and UBO disclosure, the product description with a transaction-flow narrative, and – critically – a risk assessment of the VASP's own client base. We draft and structure this package to map to the EMI's institutional questionnaire and to pre-empt the follow-on questions that delay applications by weeks.

Phase 2 – Regulatory Positioning. The VASP's legal counsel represents the entity's regulated status in a form the EMI's compliance and legal teams can rely on. This includes a legal opinion or summary on the applicable licence, the scope of regulated activities, and the AML supervisory authority. EMIs in the EU, UK and Singapore increasingly require this before the relationship committee will even review the application.

Phase 3 – Negotiation of Account Terms and Operational Limits. EMIs that accept VASPs typically do so subject to transaction-volume caps, restricted currency corridors, enhanced periodic reporting and right-to-exit clauses. These terms are negotiable. We review account agreements to identify terms that create operational risk: unilateral amendment rights, short cure periods, and reporting triggers calibrated to general retail customers rather than to a wholesale or institutional VASP operation.

Phase 4 – Ongoing Compliance Alignment. A relationship that opens is not a relationship that stays open. The EMI will conduct periodic reviews; a change in the VASP's licence status, product set or geographic reach can trigger a de-risking exit. We advise clients to maintain a standing brief that keeps the EMI relationship file current and to notify proactively rather than reactively when material changes occur.

What Are the Most Common Reasons VASP EMI Applications Fail?

In our practice, applications fail at predictable points. Understanding those points is more useful than a generic caution about "risk appetite."

The first failure mode is presenting a licence that does not match the activity. A VASP that holds a custody licence and then describes a spot-exchange operation in its product narrative creates a category mismatch that a compliance analyst will flag immediately. The licence scope and the account-use description must be internally consistent and consistent with the applicable regulatory definition.

The second failure mode is an AML programme that is drafted for a regulator rather than for a payment institution. Regulatory AML policies are written to satisfy a supervisor. A payment institution wants to know, specifically, how the VASP screens transactions in real time, what its Travel Rule solution is, which forensic tooling it uses, and what its SAR filing rate looks like. Those operational details are rarely in a regulatory policy document.

The third failure mode is entity structure opacity. A VASP that sits beneath a holding company in a non-cooperative jurisdiction, or that has UBOs disclosed only at one remove, will exhaust the EMI's compliance bandwidth. Simplifying the entity chain before the application – or at minimum documenting it with the precision a financial crime investigator would require – is preparation that pays off.

A fourth, underappreciated failure mode is timing. A VASP that approaches an EMI while its licence is under renewal, or while an enforcement inquiry is open, is presenting a relationship with unresolved regulatory risk. The right approach is to resolve or adequately disclose those facts, not to omit them. EMIs that later discover undisclosed regulatory events exit the relationship with cause.

How Does the Multi-Jurisdiction Reality Affect VASP Banking Access?

Few VASPs operate from a single jurisdiction. The entity may be domiciled in Lithuania or Malta for EU access, licensed in Dubai under VARA for the Gulf market, with custody held via a BVI or Cayman structure and banking sought through a UK or EU EMI. Each layer of that structure creates a cross-border complexity that the target payment institution must resolve before it can accept the relationship.

The practical question is not simply "which EMI will bank a VASP" but "which EMI is structurally equipped to bank this VASP, given where it is licensed, who its clients are, and what currencies it needs to move." A MiCA-authorised CASP seeking EUR settlement rails has a materially different profile from a Singapore MAS-licensed DPT service provider seeking USD and SGD access. The due diligence pack, the legal representations and the account terms differ accordingly.

We see a consistent pattern: VASPs that have mapped their licence and entity structure before approaching payment institutions succeed at a meaningfully higher rate than those approaching cold. The preparation is legal work, and it is the part of the engagement that generates the most measurable return. We regularly advise clients on structuring the entity and licence stack specifically to improve banking legibility — before the application is submitted.

A second cross-border dimension concerns client-money safeguarding. Where a VASP holds fiat on behalf of retail or institutional clients, the EMI relationship must accommodate safeguarding obligations: the separation of client funds from own funds, held in a designated safeguarding account or backed by an insurance policy. Under the EU payment-services regime and its UK equivalent, this is a regulatory requirement on the EMI, and the VASP must structure the account relationship accordingly. Failure to do so exposes both parties.

Which Structure Should a VASP Choose for Fiat Access?

The right access structure depends on the VASP's profile, its user base, and its transaction flows. There is no single answer. The matrix below describes the principal decision branches.

Profile A – EU-licensed CASP with retail clients. A CASP authorised under MiCA in a member state, serving retail users across the EEA, needs a licensed EU EMI that is prepared to hold safeguarded client funds and process retail settlement. The emphasis is on the safeguarding structure and on the AML programme's retail-customer component. The timeline from a well-prepared application to an operational account is typically measured in weeks, not months, but is subject to the EMI's own capacity and compliance review cycle.

Profile B – VARA-licensed exchange with institutional clients. A VARA-licensed entity in Dubai, operating a wholesale or institutional exchange, needs access to both AED settlement and major currency corridors. The appropriate counterparty is likely a UAE-licensed payment institution or a bank with a Gulf correspondent relationship, supplemented by a UK or EU EMI for international flows. The legal work focuses on the cross-border account structure and the contractual allocation of Travel Rule obligations between the VASP and the payment institution.

Profile C – BVI-domiciled fund with no retail VASP activity. A fund structure that holds digital assets but does not operate a public-facing exchange or custody service faces a different banking problem: it is not a VASP under most regimes, but it is still a high-risk customer for most banks. The solution is a legal memorandum establishing the entity's regulatory status – confirming that it does not trigger VASP registration requirements – and a banking approach targeted at institutions with an established digital-asset fund-client segment.

In each profile, the preparation time and the legal work are front-loaded. The application itself is the output of that preparation, not the start of it.

If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Write to OBOLUS at info@oboluslaw.com or message us at t.me/oboluslaw.

A Practical Example from Our Cross-Border Practice

In a recent matter, a licensed digital-asset exchange had its primary EMI relationship terminated without cause following an internal de-risking review at the payment institution. The client faced an operational halt within days. We prepared a revised due diligence package and a legal summary establishing the exchange's regulatory status under its home-jurisdiction VASP regime. We identified two structurally compatible EMIs in separate EU member states, submitted parallel applications, and negotiated account terms with the first institution to respond positively. The exchange resumed fiat settlement within a commercially acceptable period. The structural cause of the original exit — an undocumented change in the entity's UBO register — was identified and corrected as part of the process.

A Common Assumption About Offshore Licences and Global Access

A common assumption is that a single offshore registration provides a sufficient regulatory foundation to access banking and payment services globally. It does not. The value of any licence for banking purposes is calibrated to the credibility of the supervising authority in the eyes of the target payment institution. A registration in a jurisdiction with no public enforcement record, no published supervisory guidance and no FATF-aligned AML framework is, from a payment institution's risk perspective, evidence of regulatory arbitrage rather than regulated status.

The jurisdictions that consistently produce positive banking outcomes for VASPs are those with well-documented supervisory frameworks: MiCA-compliant EU member states, VARA in Dubai, ADGM in Abu Dhabi, MAS in Singapore, the SFC regime in Hong Kong, and the FCA's registration in the UK. This is not a coincidence. It reflects the risk calculus of the compliance teams that make the onboarding decision. We advise clients to align their primary licence to one of those frameworks before investing significant time in EMI applications — the upstream investment in the right licence is, in many cases, the only reliable route to the fiat access the business requires downstream.

Self-Assessment: Is Your VASP Ready for EMI Onboarding?

Before approaching a payment institution, a VASP's legal and compliance team should be able to answer yes to each of the following questions without qualification.

  • Does the entity hold a current licence or registration from a recognised supervisory authority, and is the licence scope consistent with the proposed account use?
  • Is the AML/KYC programme documented at the operational level — transaction monitoring, Travel Rule solution, SAR process — not merely at the policy level?
  • Is the ultimate beneficial ownership structure fully documented and free of jurisdictions that would require extended due diligence?
  • Has a legal review confirmed that the entity's regulated activities are accurately described in the due diligence package?
  • Is there a plan for client-money safeguarding if the VASP holds fiat balances on behalf of clients?
  • Is there a process for proactive notification to the payment institution of material changes to the VASP's regulatory status, product set or geographic reach?

If any answer is qualified or uncertain, that gap will surface during the EMI's compliance review. It is considerably less expensive to resolve it before the application than after a decline.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks and payment institutions close accounts with crypto companies primarily because of de-risking: the compliance cost and regulatory exposure of servicing a VASP are judged to exceed the commercial return. Contributing factors include an inadequate AML programme, an opaque ownership structure, a licence that does not match the described activity, or an undisclosed change in regulatory status. The practical remedy is not to find a more permissive institution but to resolve the underlying compliance gap before the next application. A legal review of the due diligence package typically identifies the structural cause.

How can a VASP onboard with an EMI?

A VASP onboards with an EMI by presenting itself as a regulated, AML-compliant counterparty whose risk can be assessed and contained. That requires a licence from a recognised supervisory authority, a documented AML and Travel Rule compliance programme, a clean and well-structured UBO disclosure, and a product narrative that matches the proposed account use. Legal counsel prepares and positions this package, provides any required regulatory representation, and reviews the account terms before signature. The process moves substantially faster when the preparation is complete before the first submission.

What does client-money safeguarding require?

Where a VASP holds fiat funds on behalf of clients, most regulated payment frameworks require those funds to be segregated from the VASP's own operating funds. Under EU and UK payment-services rules, the EMI holding those funds must place them in a designated safeguarding account or secure equivalent protection. For the VASP, the practical requirement is to structure the account relationship with the EMI so that safeguarded funds are ring-fenced at the point of receipt. Legal counsel reviews the account agreement to confirm that the safeguarding mechanics meet the applicable regulatory standard and that the contractual terms align with the VASP's obligations to its own clients.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, banking and compliance stack as one integrated mandate — not three disconnected workstreams — so that the payment access question is resolved alongside, not after, the licensing question. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst — specialising in payment-access structuring and AML compliance positioning for digital-asset businesses seeking EMI and banking relationships across the EU, UK, UAE and Singapore.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours