For a digital-asset business, fiat on/off-ramp banking – the infrastructure that converts crypto into conventional currency and back again – is simultaneously the most essential and the most fragile part of the operating stack. Regulators across the leading hubs are tightening their expectations on fiat on/off-ramp banking from a cross-border perspective: who holds the payment licence, where the EMI account sits, and how client money is safeguarded at each conversion point. Without the right structure, a business can find its rails frozen, its accounts closed, and its users stranded – often overnight and without prior notice.
The legal question is not simply "can we bank?" It is "which entity, licensed under which regime, can lawfully receive, convert and remit fiat funds across the jurisdictions where our users sit?" A single offshore registration rarely answers that question in full. This page maps the regulated basis, the cross-border structure, the practical process, and the common failure points that we see in cross-border on/off-ramp arrangements.
What Is Fiat On/Off-Ramp Banking in a Regulated Context?
A fiat on-ramp converts conventional currency – dollars, euros, sterling – into a digital asset; an off-ramp reverses the flow. Both legs are, in most flagship jurisdictions, regulated activities. The entity sitting at that conversion point is typically a VASP (virtual asset service provider) and, concurrently, a payment institution or EMI (electronic money institution) – or it relies on a licensed third party for the fiat leg.
Under MiCA (the EU's Markets in Crypto-Assets Regulation, supervised by ESMA and national competent authorities), a firm providing exchange services between crypto-assets and fiat currency requires a CASP authorisation. The fiat receipt and remittance functions, however, sit under the Payment Services Directive regime, meaning that a CASP that also handles fiat flows directly will typically need a payment institution authorisation or an EMI licence alongside its CASP status – or must route the fiat leg through a regulated partner.
The same layering logic applies in Singapore under the Payment Services Act supervised by MAS, where a Digital Payment Token service and a money-changing or payment function may require separate licence categories. In the UAE, VARA's activity-based licence map separates transfer and settlement activities from exchange activities, meaning that a firm conducting both legs of an on/off-ramp transaction may require more than one VARA approval.
The foundational principle is consistent: the fiat leg and the crypto leg each carry a regulatory burden. Conflating them under a single instrument – or assuming that a VASP registration alone covers fiat receipt – is one of the most common and costly structural mistakes we see.
Operating without the correct licence for both legs of the on/off-ramp exposes the business to enforcement action, account termination and, in some regimes, criminal liability for unlicensed payment activity. The risk is not theoretical; regulators in the EU, the UK, Singapore and the UAE have acted against firms that process fiat flows under an instrument that does not cover that activity.
For a scoped assessment of your on/off-ramp licensing position across the jurisdictions where you operate, contact OBOLUS at info@oboluslaw.com. The process above describes the standard layering. Your facts – the entity structure, the user base, the banking counterparties – change the analysis materially. Map your options.
How Does the Cross-Border Structure Work for On/Off-Ramp Arrangements?
The cross-border architecture of a fiat on/off-ramp arrangement turns on three questions: where is the licensed entity incorporated and supervised, where are the users located, and where does the bank account sit. Each question attracts a different legal regime, and the interaction between those regimes is where complexity – and risk – concentrates.
A business licensed in one EU member state under MiCA can passport its CASP authorisation across the EU/EEA, which resolves the crypto-layer question for European users. But the fiat payment layer is governed by the Payment Services Directive regime, which has its own passporting logic and its own competent authorities. A business that is CASP-authorised in Lithuania, for example, and that also holds a Lithuanian payment institution authorisation, can in principle passport both instruments across the EU. The operative word is "in principle": the passporting process is formal, time-bound, and requires notification and, in some cases, approval from the host member state's national competent authority. Operating in a host state before that process completes is a regulatory breach.
Outside the EU, the picture fragments sharply. A VARA-licensed entity in Dubai can serve users in the UAE under VARA's rulebooks. Serving users in the EU requires separate consideration under MiCA. Serving users in Singapore requires separate consideration under MAS's Payment Services Act. Serving users in the UK requires FCA registration under the Money Laundering Regulations and, if the firm is conducting regulated payment activity, a separate FCA authorisation under the applicable payment services regime. There is no automatic mutual recognition between these regimes.
The bank account location adds a further layer. Most correspondent banks operating in US dollars sit within the reach of FinCEN's BSA/AML framework, regardless of where the operating entity is licensed. A crypto business banking in euros through a eurozone bank will be subject to that bank's AML and PEP screening obligations, which are increasingly calibrated to the firm's CASP status and the quality of its compliance programme. In our cross-border practice, we regularly advise businesses that discover – after the fact – that their banking counterparty's internal crypto-risk policy is more restrictive than the regulatory minimum, and that the bank has closed the account without triggering a regulatory breach on its own part.
The practical upshot is that the cross-border on/off-ramp structure requires a legal map that runs from the entity layer through the licence layer to the banking layer, jurisdiction by jurisdiction, before a single fiat transaction is processed.
What Does the EMI Onboarding Process Actually Involve?
EMI onboarding for a VASP is a distinct and frequently underestimated process. An EMI (electronic money institution) is a licensed entity that issues electronic money and provides payment services; it is the infrastructure layer that many crypto businesses use to hold and move fiat funds without holding a full banking licence. The onboarding process is not simply a KYC exercise: it is a risk-committee approval that sits above the standard client-due-diligence process.
The EMI's compliance and risk teams will assess the VASP's own regulatory status, its AML/CFT programme, the jurisdictions it serves, the transaction volumes and patterns it projects, and the quality of its KYC on end-users. A VASP that cannot demonstrate CASP authorisation, MAS licensing, VARA approval or an equivalent – or that is operating under a registration that the EMI does not recognise as equivalent – will typically not proceed past the initial screening. In our practice, we have seen onboarding applications stalled or declined not because the VASP lacked a licence, but because its compliance documentation did not present the licence and the programme coherently to the EMI's risk committee.
The practical stages of EMI onboarding for a crypto business typically follow this sequence. First, a pre-application assessment: the VASP assembles its regulatory status documentation, its AML policy, its transaction monitoring framework, and its projected use-of-account profile. Second, a formal application submitted to the EMI's corporate onboarding team, including entity documents, beneficial ownership structure, and source-of-funds analysis. Third, a risk-committee review, which may include a call with the VASP's compliance officer and, in some cases, a request for enhanced due diligence on the VASP's own high-risk customers. Fourth, account provisioning, with agreed transaction limits and reporting obligations that the VASP must maintain to keep the account active.
The timeline from application to live account varies materially by EMI, by the VASP's jurisdiction of licensing, and by the complexity of the business model. A VASP presenting a simple, EU-licensed, MiCA-compliant profile with clean UBO documentation and a well-drafted AML policy may move quickly. A VASP with a multi-jurisdictional structure, offshore entities in the ownership chain, or high-risk user segments will take longer – and may require structural adjustments before the EMI will proceed.
One micro-matter illustrates the pattern. In a recent engagement, a Central Asian exchange had obtained its AFSA authorisation within the AIFC but had approached three EU-based EMIs without success. When we reviewed the application package, the compliance documentation did not translate the AIFC/AFSA framework into terms the EMIs' risk committees could assess against their own internal benchmarks. We restructured the application narrative, prepared a jurisdiction-equivalence memo, and accompanied the team through a risk-committee call. The account was provisioned within the following quarter.
Which Payment Licence Options Exist for Cross-Border Fiat Rails?
A business building cross-border fiat rails has several structural options, and the right choice depends on the operating model, the target user base, and the timeline. The decision is not primarily about cost: it is about which instrument provides the coverage, the credibility and the banking access the business actually needs.
The first option is a direct payment institution or EMI licence in a major jurisdiction. In the EU, this means a PI or EMI authorisation under the applicable payment services directive regime in a member state, with passporting rights across the EU/EEA. Lithuania, Malta and other member states have established track records of licensing payment institutions alongside CASP registrations, though the MiCA transition has introduced additional requirements. A direct EU PI/EMI licence is the strongest signal to banking counterparties and gives the firm direct control over its fiat rails.
The second option is the use of a regulated third-party payment partner. A VASP that does not hold its own payment licence routes fiat flows through a licensed PSP or EMI with which it has a commercial agreement. This is faster to implement but introduces a counterparty dependency: the PSP or EMI can terminate the arrangement, impose volume limits, or change its risk appetite, and the VASP has no direct regulatory anchor for the fiat leg. In our practice, we advise businesses that rely solely on third-party fiat rails to document the arrangement carefully and maintain a contingency banking analysis – the question of what happens if the PSP relationship ends is one that a board should be able to answer.
The third option is a hybrid approach: a VASP holds a crypto-layer CASP or equivalent licence and a limited payment authorisation (such as an account information or payment initiation service registration) while routing bulk fiat flows through a regulated bank or EMI partner under a structured commercial framework. This is the model we see most frequently among mid-market crypto businesses that have not yet reached the volume threshold to justify a full PI/EMI licence but want more resilience than a single PSP relationship provides.
A simplified decision profile follows. A retail exchange serving EU users at scale should target CASP authorisation paired with an EU PI or EMI licence, or a robust EMI partnership documented to the standard expected by the CASP's own regulator. A B2B liquidity provider operating cross-border should map each client jurisdiction separately and assess whether the fiat leg in each requires a local licence or falls within an exemption. A custody-focused business with limited fiat flows may be able to manage the fiat leg through a single regulated EMI partner, provided the business-model description in the EMI application is accurate and complete.
If a prior EMI application stalled or a banking account was closed, a second review can surface the structural reason and the route back. We regularly work with businesses that have already attempted onboarding and need a diagnostic read before the next approach. Map your options.
How Do AML and the Travel Rule Interact With Fiat Rails?
The Travel Rule – the obligation, derived from FATF Recommendation 15, to pass originator and beneficiary data alongside virtual asset transfers – creates a compliance interface between the crypto layer and the fiat layer that many businesses underestimate. When an on/off-ramp converts fiat into crypto (or vice versa), the Travel Rule applies to the crypto leg of the transaction, and the data gathered at the fiat KYC stage must be preserved and, in some cases, transmitted to the receiving VASP.
Under MiCA and the EU Transfer of Funds Regulation – which extends Travel Rule obligations to crypto-asset transfers – the interaction between fiat payment data and crypto transfer data is explicit. A CASP receiving fiat from an identified customer and converting it into crypto must associate the originator data with the subsequent crypto transfer. The fiat payment rail and the crypto transfer record must, in effect, speak to each other.
In our cross-border practice, we regularly advise that the AML programme for a cross-border on/off-ramp business must be drafted at the system level, not the transaction level. The compliance architecture must trace a user's identity from the fiat onboarding step through to the crypto destination wallet – or, on the off-ramp, from the crypto source address back to the fiat beneficiary account. A compliance programme that treats the fiat leg and the crypto leg as separate silos will fail an AML audit in any of the leading supervisory regimes.
Banking counterparties conducting their own due diligence on a VASP increasingly expect to see this integrated approach documented. An EMI onboarding a crypto exchange will ask how the exchange screens counterparty VASPs it receives transfers from, how it handles unhosted wallet transactions above applicable thresholds, and how it escalates and reports suspicious activity. The quality and specificity of the answers to those questions determine whether the account is opened and maintained – not just whether a licence exists.
FATF's Recommendation 15 and the Travel Rule apply to the crypto leg of every on/off-ramp transaction, irrespective of where the fiat counterpart settles. Businesses that treat the fiat layer as outside the VASP's compliance perimeter create a gap that regulators in the EU, Singapore, the UK and the UAE will find.
What Are the Common Structural Mistakes in Cross-Border Fiat Ramp Arrangements?
The most frequent structural error is the assumption that a VASP registration or CASP authorisation alone covers the fiat activity of the business. It does not. A CASP authorisation covers crypto-asset services as defined under MiCA. If the same entity receives fiat deposits from customers, holds those funds pending conversion, or remits fiat to customer accounts after an off-ramp, those activities are regulated under a separate payments framework. Running both under a single instrument is a regulatory breach waiting to be discovered – and the discovery typically happens when the business's bank conducts an annual review, not during a planned compliance assessment.
The second common mistake is treating banking access as a commercial problem rather than a legal and structural one. Banks that close crypto company accounts are not acting arbitrarily. They are applying their own internal risk appetite – shaped by their regulators' expectations, their correspondent banking relationships, and their own AML exposure. The businesses we see that successfully maintain stable banking relationships are those that have structured themselves to be legible to a bank's compliance team: a clear licence, a documented AML programme, a coherent UBO structure, and a use-of-account profile that matches what the business actually does.
A third error is relying on a single EMI or PSP relationship without a contingency plan. EMIs and PSPs can and do exit the crypto sector – driven by their own regulatory risk assessments, by correspondent banking pressure, or by changes in ownership. A business whose entire fiat rail runs through one provider has no operational continuity if that relationship ends. We advise clients to treat banking resilience as a structural design question, not an afterthought.
A fourth mistake, specific to the cross-border context, is assuming that a licence valid in the entity's home jurisdiction extends to users in other countries. A VARA-licensed entity in Dubai is licensed to serve UAE users under VARA's rules. Serving EU users from that entity, without either a MiCA authorisation or a MiCA-exempt local arrangement, raises a serious regulatory question. The myth that a single offshore licence is sufficient to serve clients globally is the most consequential misconception we encounter in this practice area – and the most expensive to correct after enforcement action has begun.
Self-Assessment: Is Your On/Off-Ramp Structure Legally Sound?
Before committing to an operating structure for fiat on/off-ramp services, the following questions should each have a documented answer – not an assumption.
First: does the entity holding fiat funds from customers have a payment institution or EMI licence (or an equivalent) in the jurisdiction where that activity is regulated? Or does it have a documented contractual arrangement with a licensed entity that does? Second: is the CASP or VASP authorisation covering the crypto leg of the on/off-ramp valid in each jurisdiction where users are located – or has a passporting or equivalence analysis confirmed that no additional local authorisation is required? Third: does the AML programme trace user identity and transaction data across both the fiat leg and the crypto leg, in a way that satisfies the Travel Rule obligations that apply to the crypto transfer? Fourth: is the UBO structure of the operating entity documented to the standard that a regulated EMI or bank will require at onboarding – not just to the standard of the VASP's own licensor? Fifth: does the business have at least one alternative banking or EMI relationship, or a documented contingency plan, if its primary fiat rail is terminated?
A "no" or "unsure" answer to any of these questions is a material risk. Operators we advise routinely discover gaps at this self-assessment stage – before those gaps become enforcement events or account closures. The purpose of the assessment is not to produce a clean answer: it is to identify where the structural work is needed.
Related at OBOLUS
- Banking, Payments & EMI Onboarding for Digital Asset Businesses – the full practice overview covering EMI, PI and banking access strategy.
- PSP and Acquiring Agreement Counsel for Digital Asset Firms – legal review and negotiation of PSP and acquirer agreements for crypto businesses.
- Stablecoin Freeze Requests: A Cross-Jurisdiction Comparison – how stablecoin issuer freeze authority interacts with enforcement across major forums.
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because of their own internal risk appetite, correspondent banking pressure, and AML exposure – not always because the VASP has breached a regulation. Banks apply risk policies that are often stricter than the regulatory minimum. A VASP without a clear licence, a coherent AML programme, a clean UBO structure, and a use-of-account profile that matches its actual business is likely to fail an annual account review, regardless of whether it has committed any regulatory breach.
How can a VASP onboard with an EMI?
A VASP can onboard with an EMI by presenting its regulatory authorisation, a well-drafted AML/CFT programme, a documented UBO structure, and a projected use-of-account profile that the EMI's risk committee can assess. The process typically involves a formal application, an enhanced due-diligence review, and, in many cases, a compliance call. EMIs operating in the EU increasingly expect CASP-authorised counterparties; VASPs licensed in other major regimes – MAS, VARA, AFSA – must explain the equivalence of their licensing to the EMI's risk team in terms it recognises.
What does client-money safeguarding require?
Client-money safeguarding requires a licensed entity to hold funds received from customers in a manner that protects those funds in the event of the entity's insolvency. Under EU payment services rules, this typically means holding client funds in a segregated account at a credit institution, or covering them with insurance. The precise requirements vary by jurisdiction and licence category. A VASP that holds fiat funds pending conversion, without a payment institution or EMI licence that imposes safeguarding obligations, is not in compliance – and its customers have no protected claim on those funds if the business fails.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – so that a banking closure or enforcement action does not become the trigger for the analysis that should have happened at the design stage. To discuss your on/off-ramp structure, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in cross-border VASP licensing, EMI onboarding strategy and AML/CFT compliance programme design for digital-asset businesses operating across multiple jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.