Early-stage crypto founders routinely secure a regulatory licence, incorporate in a friendly jurisdiction, and then discover that no bank will hold their operating account. The licence solves the regulatory question. It does not solve the banking question. Those are two different problems, and conflating them is the single most common and costly structural mistake we see at the founding stage.
Fiat on/off-ramp banking – the ability to accept client fiat deposits and return fiat to withdrawing users – sits at the intersection of VASP (virtual asset service provider) regulation, payment-institution rules, and the de-risking policies of correspondent banks. With regulators across MiCA, VARA, the MAS Payment Services Act regime and the FCA's money-laundering registration framework all tightening their expectations simultaneously, a founder who has not mapped the full licensing and banking stack before committing to a corporate structure faces a compounding set of exposures. This page sets out the regulated basis for fiat rails, the onboarding process for early-stage operators, the cross-border complications that routinely derail applications, and a decision matrix for the most common founder profiles.
Why Banking Is Structurally Harder Than Licensing for Crypto Startups
A VASP licence authorises you to operate; it does not oblige any bank to serve you. Banks approach crypto clients through their own internal risk-appetite frameworks, which are set independently of any regulator's licence grant. In practice, this means a founder can hold a valid authorisation from, say, the Astana Financial Services Authority (AFSA) within the AIFC or from the BVI Financial Services Commission under the VASP Act 2022, and still be declined by every Tier 1 correspondent bank in the relevant clearing chain.
The structural reason is correspondent-banking risk. A local bank that serves a VASP faces its own compliance burden with its upstream USD, EUR or GBP clearing partners. Those correspondents apply their own customer-due-diligence policies, which are often more conservative than the local regulator's standards. If the correspondent decides that the local bank's crypto exposure is too concentrated, it may withdraw the clearing line entirely – a de-risking action that can strand dozens of unrelated clients simultaneously.
In our practice, we have seen founders lose operational banking within weeks of a soft launch because the banking partner lost a correspondent relationship that the founder had no visibility into. The solution is not to find a more permissive bank. It is to structure the entity, the client-money flow and the payment layer in a way that passes the correspondent's risk model, not merely the local regulator's licensing test.
The core insight: licensing compliance and banking viability require separate legal strategies, executed in parallel, before you sign a lease or hire a compliance officer.
Operator note: the process above describes the standard path. Your facts – the entity structure, the user base geography, the banking currency and the on-chain assets – change the analysis materially.
For a scoped assessment of your banking and licence stack, contact OBOLUS at info@oboluslaw.com. We map the licence, banking and payment layers before you commit to a structure. Alternatively, map your options via the contact page.
What Fiat Rails Actually Require Legally
Running a fiat on/off-ramp means your business touches the regulated perimeter in at least two distinct ways: as a VASP and, almost always, as a payment institution or e-money participant. Understanding that dual perimeter is non-negotiable before approaching any banking partner.
On the VASP side, the applicable regime depends on where your entity is domiciled and where your users sit. A business serving EU retail users is subject to MiCA and the CASP (Crypto-Asset Service Provider) authorisation process administered by ESMA and the relevant national competent authority, regardless of where the operator is incorporated. The passporting mechanism under MiCA allows a CASP authorised in one EU member state to serve users across the EEA – but that passporting benefit applies to the crypto-asset service, not to the payment leg. The fiat leg requires a separate payment institution or e-money institution authorisation, or a contractual arrangement with an already-licensed EMI (electronic money institution).
On the payment side, accepting fiat and holding it on behalf of clients is either a regulated payment service or e-money issuance in almost every developed jurisdiction. In the EU that means compliance with the Payment Services Directive and associated national transpositions. In the UK it means FCA authorisation or registration under the Electronic Money Regulations. In Singapore it maps to the major payment institution tier under the MAS Payment Services Act. None of those regimes are satisfied by a VASP licence alone.
The practical consequence for early-stage founders is that the minimum viable legal structure for a functioning on/off-ramp is two regulated instruments, or one plus a licensed third-party payment partner. Neither instrument is obtained quickly in the major hubs; application timelines vary by jurisdiction and category, and timelines for full authorisation at leading regulators typically run to several months or more. Building the roadmap before selecting a domicile – not after – is the only way to avoid a gap in operational capability that can strand user funds.
How Does EMI Onboarding Work for a VASP?
Onboarding with an EMI is the route most early-stage founders pursue before they hold their own payment licence, and it is a viable bridge – but it comes with structural conditions that many founders do not anticipate until the application is already underway.
An EMI considering a VASP client will conduct its own risk assessment independent of any regulatory licence the VASP holds. That assessment typically covers: the VASP's own AML/CFT framework and the quality of its KYC procedures; the jurisdictions in which the VASP's users are resident; the expected transaction volumes and the fiat-to-crypto flow direction; the on-chain assets the VASP handles (stablecoins, exchange tokens and privacy coins attract different risk scores); and the ultimate beneficial ownership of the VASP entity.
A common point of failure is the geographic profile of the user base. An EMI licensed in, say, Lithuania under the Bank of Lithuania's regime may be comfortable handling EUR flows for EU-resident users but entirely unwilling to process fiat from users in higher-risk jurisdictions, even if the VASP has conducted compliant KYC on those users itself. The VASP's compliance does not substitute for the EMI's own risk appetite.
The second point of failure is the VASP's internal AML documentation. EMIs at the institutional level expect a written AML/CFT policy, a documented risk-based approach to customer screening, evidence of Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer) compliance for on-chain flows, and a named Money Laundering Reporting Officer. A founder who arrives at EMI onboarding with a template AML policy and no MLRO will almost certainly be declined, and the rejection will appear on future due-diligence questionnaires.
In a recent EMI onboarding matter, an early-stage exchange operator had incorporated in a MiCA-aligned jurisdiction and obtained preliminary regulatory clearance, but had not mapped its user geography against the EMI's own risk appetite. The EMI's decline was driven by a concentration of users in jurisdictions the EMI had internally categorised as elevated risk – a factor entirely visible in the VASP's data that had not been disclosed upfront. We restructured the onboarding disclosure package and identified an alternative EMI with an appropriate risk category for that user mix; onboarding completed within a matter of weeks on the revised approach.
Cross-Border Complications That Derail Banking Applications
The cross-border dimension of fiat rail banking is where the most serious structural traps sit, and early-stage founders are disproportionately exposed because they typically combine elements from multiple jurisdictions – a BVI holding company, an EU operating entity, a UAE commercial presence, and a user base that spans all three.
The first complication is entity-layering risk. A bank or EMI that sees a multi-entity structure with a holding company in an offshore jurisdiction and an operating subsidiary in a stricter regime will apply its KYC to every layer, including the ultimate beneficial owner. If the beneficial ownership chain is not clearly documented – or worse, if it includes nominee arrangements that obscure real control – the application will stall or be declined on AML grounds, regardless of the operating entity's licence status.
The second complication is the currency-clearing chain. An EU EMI processing USD on behalf of a VASP must route that USD through a US correspondent bank. That correspondent applies FinCEN and OFAC screening to the transaction. If the VASP's customer base includes any user from a sanctioned jurisdiction – even one who passed the VASP's own KYC – the correspondent may suspend the clearing line. The VASP and the EMI are then in breach of their respective service arrangements, and user funds may be frozen while the dispute is resolved.
The third complication is the regulatory mismatch between the VASP's licensing jurisdiction and its banking jurisdiction. A VASP licensed by the ADGM (Abu Dhabi Global Market) under the FSRA regime, operating commercially in the UAE but banking in Singapore through a MAS-supervised digital bank, faces three separate compliance frameworks simultaneously. Each has its own AML expectations, its own Travel Rule interpretation, and its own view of permissible on-chain asset types. A legal structure that satisfies all three is achievable – but it requires deliberate design, not a series of individual applications.
If a banking application has already stalled or a prior account was closed without explanation, a structural review can surface the reason and the route forward. Write to OBOLUS at info@oboluslaw.com or map your options here.
Common Mistakes Early-Stage Founders Make With Fiat Rails
The most damaging mistakes in fiat rail banking are structural rather than procedural – they are built into the entity before the first banking conversation begins, which means they are expensive to correct once identified.
The first is selecting a domicile for tax or cost reasons before confirming that a banking partner with appropriate currency clearing is available for that domicile. A number of otherwise attractive licensing jurisdictions have a thin banking market for crypto operators. Founders discover this only after incorporating and paying set-up costs.
The second is underestimating the AML documentation requirement. A VASP applying for EMI onboarding or a bank account without a complete AML/CFT framework – risk appetite statement, customer risk scoring matrix, transaction monitoring procedures, Travel Rule compliance evidence – will be declined and will have disclosed its structure to a banking counterparty it can no longer use. That disclosure cannot be undone.
The third is treating the payment licence as a later-stage problem. A founder who builds a user base on the back of a single EMI arrangement, without a parallel track toward a payment institution licence, is structurally dependent on that EMI's continued willingness to serve them. EMIs can and do terminate VASP relationships as their own risk appetite changes – often with short contractual notice. The VASP then faces the prospect of suspending fiat services to active users while scrambling for a replacement, which creates regulatory notification obligations and reputational exposure in its own right.
The fourth mistake – addressed directly in the myth below – is the assumption that a single offshore licence resolves all cross-border obligations. It does not. Regulatory obligations follow the user, not the entity.
Decision Matrix: Which Founder Profile Should Choose Which Structure?
Three profiles account for the majority of early-stage founders seeking fiat rails. Each carries a different optimal approach.
Profile A – EU-focused exchange or custody operator, seed stage. This operator intends to serve EU retail users and has a twelve-to-eighteen month runway before expected Series A. The optimal path is a CASP application in an EU member state with a proven MiCA processing record, combined with a contractual EMI arrangement during the authorisation period. The CASP application establishes regulatory standing; the EMI arrangement keeps fiat rails open while the CASP is processed. The primary risk is timeline: MiCA CASP authorisation at most EU NCAs is not a rapid process, and the EMI arrangement must be structured with a fallback if the EMI terminates during the authorisation period.
Profile B – Global token issuer or DeFi-adjacent protocol seeking fiat gateway. This operator may not require a full CASP authorisation but needs fiat on-ramp capability for token purchases or off-ramp for protocol participants. The appropriate structure turns on whether the protocol's fiat leg constitutes a regulated payment service in any jurisdiction where users are resident. In many cases it does. The right approach is a jurisdictional analysis of the user base before any payment partner is engaged, followed by either a limited payment licence in the highest-exposure jurisdiction or a careful geographic restriction enforced at the product level. The primary risk is misclassification: assuming the protocol's fiat leg is incidental when it is, in fact, the primary commercial service.
Profile C – VARA-licensed operator in Dubai banking internationally. This operator holds or is pursuing a VARA licence for activities within Dubai mainland and needs international fiat clearing, typically USD and EUR. The VARA regime is well-developed and banking partners familiar with VARA exist, but the international clearing chain remains the bottleneck. USD clearing requires a US correspondent that has approved the local bank's crypto exposure, and EUR clearing requires an SEPA-connected institution willing to onboard a UAE-domiciled VASP. In our practice, the solution typically involves a combination of a local UAE banking relationship for AED and regional flows, and a MAS-regulated or FCA-registered payment institution for USD and EUR legs, held in a correctly structured group entity.
A Common Assumption About Offshore Licences – and Why It Is Wrong
A common assumption among early-stage founders is that a single offshore licence – a Cayman VASP registration under the CIMA regime, a BVI VASP Act registration, or a structure in another low-overhead jurisdiction – is sufficient to serve clients globally while managing regulatory risk. This assumption is incorrect, and acting on it creates the exact enforcement exposure it is designed to avoid.
The error lies in conflating the jurisdiction of incorporation with the jurisdiction of service. Under MiCA, an operator providing crypto-asset services to EU-resident users is subject to the MiCA regime regardless of where it is incorporated. Under the FCA's regime, a business marketing cryptoassets to UK consumers must comply with the UK financial-promotion rules regardless of whether it has a UK entity. The MAS regime in Singapore applies to a business providing digital payment token services to Singapore users even if that business operates from outside Singapore.
The principle is consistent across leading jurisdictions: regulatory obligations attach to the user's location, not the entity's registration address. An offshore licence may reduce compliance costs in the licensing jurisdiction. It does not insulate the operator from the regulatory requirements of every jurisdiction where its users reside.
For a business with a genuinely global user base, the correct structure is either a series of jurisdictional licences or authorisations matched to the major user geographies, or a geographic restriction enforced at the product and KYC level that is legally defensible in the restricted jurisdictions. Attempting to serve users globally on the basis of a single offshore registration is not a grey area in most developed regulatory regimes – it is a defined enforcement risk.
Self-Assessment Checklist Before Your First Banking Conversation
Before approaching a bank or EMI, a founder should be able to answer the following questions affirmatively. An inability to answer any of them is a structuring gap that will surface during due diligence.
Is the VASP's ultimate beneficial ownership documented to the AML standard of the target banking jurisdiction, including the source-of-wealth explanation for each UBO above the applicable threshold? Is there a written AML/CFT policy, a risk-based customer scoring matrix and a designated MLRO in place? Is the Travel Rule compliance approach documented for on-chain transfers, including the technical solution for passing originator and beneficiary data? Is the user geography profiled by jurisdiction and matched against the banking partner's known risk-appetite exclusions? Is the entity structure – including any holding-company layer – explainable in plain terms to a compliance officer who has never seen the corporate chart before? And has the payment layer been assessed separately from the VASP licence, with a clear answer on whether a payment institution authorisation is required?
If any of these is unanswered, the banking application will either be declined or will take materially longer than necessary. The cost of preparing these materials before the first approach is substantially lower than the cost of rebuilding credibility after a decline.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital-Asset Businesses – how we structure the full payment and banking layer for operators at every stage
- De-Risking and Account Closure Defence in the Bahamas – what to do when a banking relationship is terminated and how to defend against de-risking in offshore hubs
- Security Token Offering Structuring – the Disputes Angle – how structural decisions made at the token-issuance stage affect later litigation exposure
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because of correspondent-banking pressure rather than direct regulatory instruction. A bank's upstream USD or EUR clearing partner may restrict or withdraw the clearing line if the local bank's aggregate crypto exposure is considered too high, forcing account terminations that have nothing to do with any individual VASP's compliance record. Direct causes include inadequate AML documentation on the VASP's side, geographic concentration of users in elevated-risk jurisdictions, unclear beneficial ownership, and the presence of on-chain assets – such as privacy coins – that the bank's internal policy excludes. Structural preparation before account opening, not remediation after closure, is the effective response.
How can a VASP onboard with an EMI?
A VASP can onboard with an EMI by presenting a complete compliance package that satisfies the EMI's own risk-assessment process, which is independent of any regulatory licence the VASP holds. That package should include a written AML/CFT policy, a customer risk-scoring methodology, Travel Rule compliance documentation, a named MLRO, full beneficial ownership disclosure, and a profiled user geography matched against the EMI's risk appetite. Partial or template documentation is the most common cause of EMI decline at the early stage. Engaging the EMI through a structured approach – with the disclosure package prepared in advance – materially improves the outcome and reduces the timeline.
What does client-money safeguarding require?
Client-money safeguarding requires a licensed payment institution or EMI to hold funds received from clients in designated safeguarded accounts, separate from the operator's own funds, with a regulated credit institution or central bank. The exact requirements vary by jurisdiction and licence category: under EU payment-services rules, under the FCA's EMI regime, and under the MAS Payment Services Act, the safeguarding obligation is a core condition of authorisation, with prescribed methods of compliance. A VASP that holds client fiat without a payment licence – or without a formal arrangement with a licensed partner – is likely operating outside the regulated perimeter, which creates both regulatory and insolvency-law exposure for client funds.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the full licence, payment and banking stack before you commit to a structure – covering the operating, custody and payment layers together, not in isolation. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when banking relationships fail and funds are at risk. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory and Compliance Analyst – specialising in VASP licensing, payment institution onboarding and the cross-border regulatory compliance stack for digital-asset operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.