EST · MMXXVI
Home/Services/Banking Payments Emi/EMI onboarding for vasps under Heightened Scrutiny
Banking, Payments & EMI Onboarding

EMI onboarding for vasps under Heightened Scrutiny

Emi onboarding for vasps under Heightened Scrutiny. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

A virtual asset service provider operating without stable fiat rails is running on borrowed time. The exchange may clear trades, the custody solution may hold balances, and the compliance stack may pass an internal audit – but if the EMI relationship collapses on a Tuesday morning, client withdrawals halt by Tuesday afternoon. In our practice, the gap between a well-structured VASP and one that folds under banking pressure is rarely technical. It is almost always a question of preparation: whether the business walked into the onboarding conversation with the right documentary architecture, the right entity structure, and a clear account of how its own regulated perimeter fits the Electronic Money Institution (EMI) risk appetite.

This page maps the regulated basis for EMI onboarding under heightened scrutiny, the process and common failure points, the cross-border reality of multi-rail structuring, and a decision matrix for operators at different stages of their licence journey. The framework is applicable across the leading hubs – from MiCA-authorised CASPs (Crypto-Asset Service Providers) seeking EU payment rails to exchange operators working through the VARA regime in Dubai or the MAS Payment Services Act regime in Singapore.

Why EMIs Treat VASPs Differently

An EMI's exposure to a VASP client is categorically different from its exposure to a retail merchant or a payroll provider. The EMI assumes reputational, regulatory and financial-crime risk the moment it issues an IBAN or processes a fiat settlement for a virtual asset business. Most EMI compliance teams are working from guidance issued by their home regulator – whether that is the FCA in the United Kingdom under the Money Laundering Regulations, ESMA and the relevant national competent authority under MiCA, or MAS under the Payment Services Act – and that guidance uniformly treats VASPs as higher-risk counterparties. The practical consequence is that standard SME onboarding flows do not apply. An EMI that accepts a VASP without enhanced due diligence is itself in breach of its AML obligations.

The scrutiny is structural, not arbitrary. A VASP typically aggregates transaction flows from a large, pseudonymous user base. The underlying assets move on public ledgers, but the beneficial ownership of any given wallet may pass through multiple layers before a fiat settlement request arrives at the EMI. From the EMI's perspective, a VASP is a high-volume, high-opacity correspondent – exactly the profile that FATF Recommendation 15 and the Travel Rule were designed to address. EMIs that miscalibrate here face enforcement from their own regulator.

In our cross-border practice, we have seen well-capitalised exchanges lose EMI relationships not because of any AML failure on their part, but because the EMI's group-level risk appetite shifted following a supervisory visit. The VASP had no early warning. The relationship terminated with thirty days' notice. That pattern is repeating across multiple jurisdictions as supervisors tighten their expectations of payment institutions operating in the digital-asset space.

What the Regulated Basis Requires

Before an EMI can open and maintain accounts for a VASP, it must satisfy its own regulator that the relationship is managed within its risk framework. That requirement flows directly from the AML/CFT baseline set by the FATF Recommendations and implemented locally – under MiCA and the associated anti-money-laundering directives in the EU, under the Money Laundering Regulations in the UK, under the applicable VASP provisions in the UAE, and through the Payment Services Act and MAS notices in Singapore.

The EMI must treat the VASP as a business customer subject to enhanced due diligence (EDD) – a deeper level of scrutiny applied to customers who present higher money-laundering risk. EDD typically involves verification of the VASP's own regulatory status, review of its AML/KYC policy documentation, an assessment of its user-base geography, a review of expected transaction volumes and patterns, and – increasingly – an on-site or virtual meeting with senior compliance personnel. Some EMIs also require evidence of the VASP's own Travel Rule solution: the technology used to pass originator and beneficiary data with transfers, as required under the applicable regime.

The regulated basis also shapes what the EMI can offer. An EMI is not a bank. It issues electronic money and provides payment services; it does not accept deposits or extend credit. That distinction matters for VASPs structuring their treasury. Funds held with an EMI under the safeguarding obligation are client money, ring-fenced from the EMI's own balance sheet – but the instruments available are narrower than those offered by a credit institution. Understanding that boundary before onboarding prevents the misallocation of treasury that we regularly see in early-stage operators.

To map your entity structure against the EMI risk tier that applies to your business, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options

The Onboarding Process: Step by Step

EMI onboarding for a VASP under heightened scrutiny runs in distinct stages, each with its own documentation requirement and common failure point. Understanding the sequence allows the operator to prepare in parallel rather than serially – compressing a process that can otherwise take several months.

Stage one is pre-qualification. Before submitting a formal application, the VASP should map its own licence status, corporate structure and anticipated transaction profile against the EMI's published acceptance criteria. Most EMIs with digital-asset appetite publish a high-level scope on their website or in their terms of business. Operators that skip this step frequently invest significant compliance time building an application that fails at the first screening call because the EMI does not accept their jurisdiction of incorporation or their primary product category.

Stage two is the documentary package. A well-prepared package for a VASP applicant typically includes: the VASP's own regulatory licence or registration certificate; the group structure chart showing all entities and beneficial owners above the relevant threshold; the AML/KYC policy, including the Travel Rule implementation approach; a transaction volume projection by currency and corridor; a geographic breakdown of the anticipated client base; and a source-of-funds analysis for the initial operating capital. The package must be internally consistent. Inconsistencies between the AML policy and the transaction projections are the single most common early rejection point we observe.

Stage three is the enhanced due diligence interview. The EMI's compliance team will want to speak directly with the VASP's MLRO or equivalent. This is not a formality. The EMI is assessing whether the VASP's AML culture matches its documentation – whether the people who own the compliance function understand it. Operators that have recently appointed a nominal MLRO without substantive involvement typically fail this stage.

Stage four is ongoing monitoring obligations. A successful onboarding does not end the scrutiny. The EMI will typically require quarterly or annual refresh of the KYB file, prompt notification of any regulatory change affecting the VASP, and adherence to transaction-monitoring thresholds. Operators that treat onboarding as a one-time exercise rather than a continuing relationship management function accumulate risk silently until an account suspension notice arrives.

Common Mistakes That Kill EMI Applications

The most common reason a VASP's EMI application fails is not non-compliance – it is incomplete preparation. Experienced EMI compliance teams review hundreds of applications; they can identify under-prepared operators within minutes of opening the file. The following patterns recur in our practice.

First, presenting a corporate structure without a clear compliance narrative. A holding company in one jurisdiction, an operating entity in a second, and a technology subsidiary in a third is not inherently problematic – but the application must explain why the structure exists, who controls it and how funds flow through it. A structure chart without that narrative reads as obfuscation, even if the design is entirely legitimate.

Second, submitting an AML policy that is a template. EMIs in the digital-asset space have seen every standard industry template. A policy that does not reflect the VASP's actual product, user base and transaction architecture will fail the EDD review. The policy must be operational, not aspirational.

Third, underestimating the Travel Rule question. The Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer) is now a live compliance expectation in every major jurisdiction – under MiCA in the EU, under VARA in Dubai, under the MAS regime in Singapore and under the FCA's registration regime in the UK. EMIs will ask which Travel Rule solution the VASP uses. An answer of "we are evaluating options" is treated as a red flag. The VASP must have a deployed solution and be able to describe its operation.

Fourth, failing to anticipate the correspondent-banking layer. An EMI is itself dependent on a sponsor bank for its own settlement. If the VASP's business profile exceeds what the EMI's sponsor bank will accept, the EMI cannot onboard regardless of its own appetite. The VASP needs to understand the entire rail, not just the EMI layer.

Cross-Border Structuring for Fiat Rails

Operating across jurisdictions multiplies the banking complexity in ways that a single-entity analysis will miss. A VASP licensed under VARA in Dubai serving European retail clients will need EU-resident payment capacity to meet the MiCA expectation for CASP-to-client settlements; it cannot simply route EUR settlements through a UAE-domiciled EMI. Similarly, a Cayman-registered fund investing in digital assets may need a Singapore-resident payment layer for SGD settlements under the MAS Payment Services Act, even if the fund itself is not a DPT service provider.

The cross-border structuring question turns on three axes: where the regulated activity occurs, where the clients are located, and where the currency settlement must legally land. Those three points rarely align naturally. Operators that treat banking as a single-jurisdiction problem consistently find themselves with a structural mismatch when the regulator in a secondary market asks for evidence of local payment capacity.

We advise clients to map the rails before they map the licence. The licence is the permission to operate; the rail is the mechanism of operation. A business that obtains a MiCA CASP authorisation with a Lithuanian national competent authority has EU passporting rights for regulated activities – but if it cannot settle EUR client withdrawals through an EMI that its sponsor bank will support, the licence does not translate into a functional product.

In a recent matter, a payments company structuring a multi-jurisdiction crypto-to-fiat settlement product engaged us to review its banking architecture before it submitted its EMI onboarding applications. The entity had strong regulatory credentials but had built its corporate structure around a single offshore holding vehicle that created a beneficial ownership disclosure gap in two of the three target jurisdictions. We restructured the group before any application was submitted, and the operator successfully onboarded with two EMIs across EU and Gulf corridors without a rejection.

If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Reach the OBOLUS banking and payments desk at info@oboluslaw.com or map your options here.

Decision Matrix by Operator Profile

Not every VASP approaches EMI onboarding from the same starting position. The appropriate strategy depends on the operator's regulatory status, jurisdiction, transaction profile and client base. The following profiles represent the common configurations we encounter.

Profile A: EU-licensed CASP (MiCA CASP authorisation, single member state). This operator has the strongest position for EU EMI onboarding. The CASP authorisation signals to the EMI that the VASP has passed regulatory scrutiny. The primary challenge is demonstrating that the AML function meets the EDD standard, not merely the CASP authorisation minimum. Timeline to onboarding, with a well-prepared package, is typically a matter of weeks rather than months – though specific timelines vary by EMI and application complexity. Key risk: the EMI's sponsor bank may still apply group-level restrictions on crypto clients regardless of CASP status.

Profile B: VARA-licensed operator (Dubai, mainland). The VARA regime is well-regarded among EMIs with Gulf exposure, but has limited recognition among EU EMIs. A VARA-licensed operator seeking EUR rails will almost always need a separately incorporated EU entity to access MiCA-compliant payment capacity. The dual-entity structure adds cost and complexity but is the only reliable route to European fiat settlement. Timeline depends on the pace of EU entity formation and subsequent CASP notification or authorisation.

Profile C: MAS-regulated DPT service provider (Singapore). Singapore's Payment Services Act DPT licence is recognised by EMIs in the APAC corridor and by select UK-regulated EMIs. It has limited reach into EU payment rails without an additional EU presence. Key risk: the transition between licence tiers under the Payment Services Act framework can create temporary coverage gaps that interrupt EMI relationships mid-onboarding.

Profile D: Unregistered or lightly registered operator (BVI, Cayman, offshore). This is the highest-friction scenario. An operator without registration under a recognised VASP regime – BVI FSC, CIMA, or a full CASP/VARA/MAS authorisation – will face the most intensive EDD and the highest rejection rate. The practical advice is to obtain at minimum a registration under the applicable VASP Act before approaching EMIs. Allied counsel in the relevant jurisdiction can accelerate that process.

What Client Money Safeguarding Means in Practice

Client-money safeguarding is the EMI's core prudential obligation and a critical compliance area for any VASP using EMI-issued payment accounts to hold client balances. Under the safeguarding rules applicable to EMIs – whether under the EU's Payment Services Directive, the UK's equivalent regime, or analogous local rules – the EMI must hold client funds in a dedicated safeguarding account or invest them in liquid, low-risk assets. Those funds sit outside the EMI's own insolvency estate.

For a VASP, this has direct operational implications. The VASP cannot simply treat EMI-held balances as a treasury pool. The EMI will monitor how the VASP categorises incoming and outgoing flows. If the VASP commingles operational funds with client balances in its EMI accounts – a pattern we see regularly in early-stage operators – both the VASP and the EMI are exposed: the VASP for a breach of its own client-asset obligations, and the EMI for a safeguarding failure.

Operators structuring multi-currency treasury arrangements across EMI and bank rails also need to be precise about which entity holds which funds. A holding company that sweeps treasury balances from an operating VASP's EMI account may inadvertently create a client-money breach at the operating entity level, depending on the terms of the sweep arrangement and the jurisdiction of the operating entity's own regulatory licence. This is a structural question that should be resolved before onboarding, not discovered during a routine EMI compliance review.

The Self-Assessment Checklist

Before approaching an EMI, a VASP should be able to answer yes to each of the following questions. In our experience, operators that cannot answer yes to all of them should address the gap before submitting an application.

  • Is the VASP registered or licensed under a recognised VASP or CASP regime (VARA, MiCA, MAS, SFC, BVI FSC, CIMA or equivalent)?
  • Does the VASP have a current, bespoke AML/KYC policy that reflects its actual product and user base?
  • Is the Travel Rule solution deployed and operational, with evidence available for the EMI's review?
  • Is the corporate group structure documented, with beneficial ownership verified and disclosed above the applicable threshold?
  • Has the VASP prepared a transaction volume projection by currency and corridor, consistent with its AML risk assessment?
  • Is the MLRO or equivalent compliance officer substantively involved in the business and able to lead an EDD interview?
  • Has the VASP identified the full rail – including the EMI's sponsor bank – and confirmed that its business profile falls within that sponsor bank's acceptance criteria?
  • Has the VASP mapped client-money flows to ensure EMI accounts will not be used to commingle operational and client balances?

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close accounts for digital-asset businesses primarily because of perceived regulatory and reputational risk. A VASP aggregates transaction flows from a large, often pseudonymous user base, which creates heightened anti-money-laundering exposure for the bank. Banks also face group-level restrictions from their own regulators or correspondent banking partners. A clear regulatory licence, a strong AML framework and transparent documentation of transaction flows reduce – though do not eliminate – that risk. Operators that can demonstrate CASP, VARA or equivalent authorisation are better positioned to retain banking relationships than unregistered entities.

How can a VASP onboard with an EMI?

A VASP onboards with an EMI by satisfying the EMI's enhanced due diligence requirements. The process involves submitting a documented package covering the VASP's regulatory status, corporate structure, AML/KYC policy, Travel Rule solution and projected transaction profile. A compliance interview with the EMI's team follows. Preparation is the determinant of success: operators with a clear compliance narrative, a deployed Travel Rule solution and a group structure that is straightforward to explain consistently achieve faster onboarding than those who approach the EMI without a pre-qualified documentary file.

What does client-money safeguarding require?

Client-money safeguarding requires an EMI to hold funds received from customers in a dedicated account separate from the EMI's own assets, or in qualifying liquid instruments. For a VASP using EMI accounts to hold client fiat balances, this means the VASP must not commingle client and operational funds in those accounts. The practical requirement is a clear internal segregation of client balances, documented in the VASP's own treasury policy and reflected in its instructions to the EMI. Failure to segregate correctly creates regulatory exposure for both the VASP and the EMI.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses – not retail clients. We map the licence stack across operating, custody and payment layers before you commit, so structural mismatches are identified before an application is filed or an account is opened. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP authorisation, EMI onboarding architecture and cross-border AML compliance for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours