Operating a digital-asset business without resolved fiat rails is not a compliance gap – it is an existential one. A crypto exchange, custodian or payments firm that cannot reliably move funds between the banking system and its clients' on-chain balances will lose customers, fail settlement obligations and attract regulatory scrutiny at the worst possible moment. The legal question is almost never whether a firm needs banking access; it is how to structure the entity, the licence stack and the compliance programme so that a bank or electronic money institution (EMI – a payment firm authorised to issue e-money and hold client funds) will open and maintain an account. As regimes converge on the MiCA model and global supervisors tighten virtual asset service provider (VASP – any firm offering exchange, transfer or custody of digital assets) oversight, the bar for banking access has risen sharply. This page explains what legal counsel on fiat on/off-ramp banking covers, how the process works in practice, where it goes wrong and what the right structure looks like across jurisdictions.
The Regulated Basis for Fiat On/Off-Ramp Access
A digital-asset firm's ability to access fiat rails (the payment infrastructure connecting bank accounts, card networks and settlement systems to on-chain activity) depends on satisfying a layered set of regulatory conditions – not simply registering an entity in a convenient jurisdiction. Banks and EMIs that service crypto firms are themselves supervised: the FCA in the United Kingdom, the Bank of Lithuania and other national competent authorities under MiCA, the Monetary Authority of Singapore under the Payment Services Act, and their counterparts in every major financial centre each impose enhanced due diligence obligations on institutions providing correspondent or account services to VASPs. Those institutions pass that scrutiny onto their crypto clients.
What this means in practice is that a digital-asset firm seeking a bank account is, in effect, undergoing a secondary regulatory examination. The bank or EMI reviews the firm's own licence status, its AML/CFT (anti-money laundering and counter-terrorist financing) programme, its beneficial ownership structure, its transaction monitoring capacity and its Travel Rule compliance posture. The Travel Rule is the obligation – drawn from FATF Recommendation 15 and implemented across the major hubs – to transmit originator and beneficiary data alongside virtual asset transfers above the applicable threshold. A firm that cannot demonstrate Travel Rule readiness will not secure institutional-grade banking in any leading hub.
The regulated basis therefore spans three layers simultaneously: the firm's own licence or registration (the VASP, CASP or payments authorisation), the banking institution's own compliance requirements and the cross-border AML posture of every jurisdiction in which the firm operates or has users. Getting one layer right and neglecting the others is the most common reason banking relationships stall.
Practical note: A firm domiciled in one jurisdiction but serving users in another frequently triggers licensing obligations in the user's jurisdiction, not only the firm's home jurisdiction. Under MiCA, for example, a CASP authorised in one EU member state may passport across the EEA – but it must notify the host competent authority, and its banking partner will verify that the passporting notification was made correctly. Failing that step will cause the account application to fail at compliance review.
What Legal Counsel on Fiat On/Off-Ramp Banking Actually Covers
Legal counsel on fiat on/off-ramp banking is not a single engagement; it is a structured advisory process covering entity structuring, licence adequacy review, banking-pack preparation and ongoing relationship management. In our practice, we begin every mandate with a diagnostic across the operating, custody and payment layers before any bank or EMI is approached.
The diagnostic examines five questions. First, does the firm hold the right licence for its activity profile? A firm that converts fiat to crypto for retail customers in the EU needs a CASP authorisation under MiCA; the same firm holding client funds en route also likely needs payment institution or EMI authorisation. Second, does the firm's AML programme meet the standard a supervising bank will expect? Third, is the corporate structure transparent – meaning that the beneficial ownership chain is documented, clean and explainable to a compliance officer who has never seen the crypto sector before? Fourth, is the firm's transaction monitoring and Travel Rule infrastructure operational, not merely planned? Fifth, is the jurisdiction of incorporation appropriate for the banking market the firm needs to access?
Only after those questions are answered do we assist in identifying the right banking or EMI counterparty and preparing the account-opening pack. That pack typically includes a legal opinion on the firm's licensing status, a compliance programme summary, a product walkthrough demonstrating how fiat flows are controlled, AML policy documentation and a business plan. The difference between a pack that passes compliance review and one that does not is almost always the quality of the legal opinion and the precision of the AML documentation – not the commercial pitch.
CTA #1: The process above describes the standard path. Your facts – the entity, the user base, the banking jurisdiction – change the analysis significantly. For a scoped assessment of your on/off-ramp structure, contact OBOLUS at Map your options.
What Does the Banking Onboarding Process Look Like?
Banking onboarding for a digital-asset firm typically proceeds in three phases, each with a distinct legal content.
Phase one is preparation. This covers entity structuring (or re-structuring where an existing entity is not bankable), licence gap analysis, AML programme review and documentation assembly. The duration of this phase depends almost entirely on the state of the firm's existing compliance infrastructure. A well-prepared firm with an existing licence and a documented AML programme can complete preparation in a matter of weeks. A firm starting from scratch – entity, licence and compliance programme all to be built – should plan for several months before the first bank approach.
Phase two is the bank or EMI selection and approach. Selection criteria include the institution's existing appetite for digital-asset clients (some institutions have dedicated crypto desks; others have exited the sector), the jurisdiction in which the account is needed, the currencies required and the settlement rails the firm's business model depends upon. We maintain working familiarity with the banking market across the major hubs and can assist in targeting approaches efficiently. The compliance review period at a prospective banking institution varies: lighter-touch institutions may complete their review in a matter of weeks; a correspondent bank at a primary financial centre may take several months.
Phase three is ongoing relationship maintenance. Banking relationships with digital-asset firms are not static. Periodic enhanced due diligence requests, transaction monitoring queries and licence renewal reviews are standard. A firm that manages these proactively – providing timely responses, flagging regulatory changes and maintaining clean AML records – materially reduces the risk of an account being placed under review or closed.
What Are the Most Common Mistakes That Kill Banking Applications?
The most destructive mistake is approaching a bank before the firm's licence and compliance programme are in place. Banks and EMIs onboarding digital-asset clients are supervised for the quality of their own due diligence. An approach from a firm that does not yet hold the relevant authorisation – or that holds an authorisation that does not cover the activities the firm actually performs – will result in an immediate decline, and that decline may be shared within the correspondent banking network.
The second most common failure is structural opacity. A beneficial ownership chain that passes through multiple holding layers in multiple jurisdictions, without a clear and documented rationale, triggers automatic enhanced scrutiny. A compliance officer reviewing a crypto firm's account application will map the ownership structure looking for politically exposed persons, sanctions exposure and unexplained complexity. Legal counsel assists in ensuring the structure is both legitimate and legible.
Third is over-reliance on a single banking relationship. Operators we advise routinely discover that concentration risk in banking is as dangerous as concentration risk in any other critical infrastructure. A firm whose entire fiat settlement depends on one account at one institution is one compliance review away from an operational crisis. A correctly structured firm maintains relationships across at least two institutions in two jurisdictions, with documented contingency arrangements.
Fourth – and particularly relevant for firms expanding internationally – is the failure to account for host-jurisdiction requirements when using a passported or cross-border licence. The fact that a firm holds a valid licence in its home jurisdiction does not automatically satisfy the banking compliance requirements of every jurisdiction in which it operates. We see this most often with firms using an EU MiCA authorisation to serve users in non-EEA markets, or with firms using a BVI or Cayman registration to access banking in a G10 market. The home licence matters; so does the full picture.
How Does the Cross-Border Reality Affect Fiat Rail Access?
For a digital-asset business operating across more than one jurisdiction – which describes the majority of exchanges, custodians and payment firms – the legal question around fiat rails is inherently multi-dimensional. Where the entity sits, where its users are, where its banking lives and where its assets are held are four distinct questions, and the answer to each constrains the others.
A firm incorporated in the BVI under the BVI FSC's VASP Act regime, serving EU retail users, will find that its BVI registration does not constitute a MiCA CASP authorisation and therefore does not satisfy the due diligence requirement of a eurozone EMI. To access euro-denominated rails for EU users, it needs either a MiCA CASP authorisation in an EU member state, an EMI licence in an EU member state, or a contractual arrangement with a licensed intermediary that is itself regulated under MiCA. Each option has a different cost structure, timeline and ongoing compliance burden.
Similarly, a Singapore-licensed firm under the MAS Payment Services Act – holding a Major Payment Institution licence for Digital Payment Token services – will find that its Singapore authorisation does not automatically satisfy UK FCA due diligence expectations. If the firm wants sterling settlement or a UK correspondent bank, it needs either FCA cryptoasset registration under the Money Laundering Regulations or a bilateral relationship with an FCA-authorised intermediary.
In our cross-border practice, we regularly advise on the minimum licence stack required to access the specific banking markets a firm needs – not the maximum theoretical stack. The goal is to identify the most efficient combination of authorisations and entity structures that opens the required fiat rails without unnecessary regulatory overhead. Allied counsel in the relevant jurisdiction are engaged where local licensing work is required alongside the cross-border structuring advice.
The AIFC/AFSA regime in Kazakhstan and the ADGM/FSRA framework in Abu Dhabi each offer banking access pathways that are relevant for firms serving Central Asian and Gulf markets respectively. Both regimes have developed institutional banking ecosystems alongside the regulatory authorisation, which is a practical advantage when the firm's target user base is concentrated in those regions.
A Practical Illustration: Payments Firm, Two Banking Failures
In a recent matter, a payments firm that had operated for several years using a single EMI relationship in a mid-tier EU jurisdiction found its account placed under review following a change of control. The firm had assumed its existing MiCA transitional registration would be sufficient to maintain the relationship. It was not. The acquiring entity had introduced a group-level crypto risk policy that required all digital-asset business to hold full CASP authorisation rather than a transitional status. We reviewed the firm's existing compliance programme, identified the gap between its transitional status and the CASP authorisation requirements, structured a revised corporate arrangement using a properly authorised affiliate as the contracting entity, and prepared a revised onboarding pack. The account was restored on the revised structure, and the firm concurrently engaged banking in a second jurisdiction as a contingency. The matter resolved within a matter of months from our initial instruction.
Which Structure Fits Which Operator Profile?
The right on/off-ramp structure depends on the operator's activity profile, user base and target banking markets. Three illustrative profiles demonstrate how the analysis works in practice.
Profile A – Retail exchange, EU focus: A firm operating a crypto-to-fiat exchange for EU retail users requires a MiCA CASP authorisation in at least one EU member state, with notification to the competent authorities in every member state where users are actively onboarded. It will also need either an EMI licence or a relationship with a licensed EMI to hold client fiat balances. The likely banking route is through a dedicated digital-asset EMI or a challenger bank with an established crypto compliance desk. The key risk is failing to complete the passporting notification before the bank's own compliance review, which triggers a gap in the firm's regulated status that the bank cannot overlook.
Profile B – Institutional OTC desk, multi-jurisdictional: A firm providing over-the-counter large-ticket digital-asset transactions for institutional counterparties across multiple jurisdictions requires a more complex licence stack. It will typically need authorisation in each jurisdiction where institutional counterparties are domiciled, or a carefully structured arrangement relying on the institutional counterparty's own regulatory perimeter. Banking access for an OTC desk is often through a prime brokerage or a treasury management relationship at a Tier 1 institution; the due diligence bar is correspondingly high and typically requires a multi-year audited financial history alongside the compliance documentation.
Profile C – Payments firm, emerging-market corridor: A firm moving fiat-to-crypto-to-fiat across a corridor that includes a market without developed VASP regulation – common in cross-border remittance – typically needs a combination of a licence in the firm's home jurisdiction, a Money Services Business or equivalent registration at the sending end, and a correspondent banking relationship that can accommodate the corridor's risk profile. The BVI VASP Act, the Cayman VASP framework and the AIFC/AFSA regime each have specific strengths for different corridor profiles. The key risk is that the corridor's risk rating at the correspondent bank changes following a FATF grey-listing of a country in the payment chain, triggering an account review.
CTA #2: If a prior application stalled or a banking relationship was closed, a structured second review can identify the underlying cause and the route back. Write to OBOLUS at Map your options to begin that review.
A Common Assumption: One Offshore Licence Is Enough
A common assumption among firms building their first digital-asset operation is that a single offshore registration – in the BVI, Cayman Islands or a comparable jurisdiction – is sufficient to support both regulatory compliance and banking access globally. In our experience, this assumption is the single most expensive mistake a digital-asset business can make at the formation stage.
An offshore registration is a legitimate and often useful component of a digital-asset structure. It is not a substitute for the licences and registrations required in the jurisdictions where the firm's users, banking and payment counterparties are actually located. A Cayman VASP registration does not satisfy MiCA. A BVI registration does not satisfy the FCA's MLR requirements. Neither satisfies the MAS Payment Services Act requirements for a DPT service provider operating in Singapore.
The practical consequence is that firms relying on a single offshore registration frequently find themselves in the following position: the registration is technically valid in its home jurisdiction, the firm has been operating without incident, and then a banking institution – under pressure from its own regulator or following a group-level policy review – declines or closes the account on the basis that the firm does not hold an authorisation recognised by the institution's primary regulator. At that point, the firm faces a choice between a rushed licence application in a jurisdiction it did not plan for, an operational pause while banking is re-established, or a re-domiciliation. All three options are expensive and time-consuming. The correct approach is to map the full licence and banking stack at inception.
Self-Assessment: Is Your Fiat Banking Structure Ready?
Before approaching a bank or EMI, operators should be able to confirm the following. Each item represents a threshold question that a banking compliance team will examine.
First, the firm holds a licence or registration that covers its actual activities in each jurisdiction where it operates or onboards users – not a registration in a jurisdiction it chose for convenience. Second, the beneficial ownership structure is documented, current and capable of being verified by a third party within 48 hours of a compliance request. Third, the firm has an operational AML programme – policies, procedures, transaction monitoring and a named compliance officer – not a draft. Fourth, Travel Rule compliance is in place for all applicable transfer thresholds, with a named technology solution and a process for handling unhosted wallet transactions. Fifth, the firm has identified at least two prospective banking counterparties and has assessed their current appetite for digital-asset clients. Sixth, the firm's product documents – terms of service, fee schedules, user agreement – are consistent with the regulatory scope of its licence.
Regulators in the leading hubs increasingly expect digital-asset firms to demonstrate that their compliance programmes are not merely paper-based but operationally tested. A bank reviewing a new digital-asset account will probe the gap between the written programme and the actual operational practice.
Related at OBOLUS
- Banking, Payments & EMI Onboarding for Digital-Asset Businesses – the full practice overview covering EMI licensing, payment institution authorisation and fiat-rail strategy across jurisdictions.
- PSP and Acquiring Agreement in Georgia – how Georgia's payment services regime creates a practical fiat on-ramp option for digital-asset firms serving CIS and emerging-market corridors.
- How to Choose a Crypto Licensing Jurisdiction – a structured decision guide for selecting the right licensing home based on activity profile, banking market and user base.
FAQ
Why do banks close crypto company accounts?
Banks close crypto accounts most often for one of four reasons: the firm's licence does not cover the activities the bank has observed in its transaction monitoring; the firm's AML programme fails a periodic enhanced due diligence review; the bank's own regulator has imposed category-level restrictions on digital-asset business; or a change in the bank's group-level risk policy reclassifies crypto clients as outside appetite. The common factor is a mismatch between the firm's regulatory posture and the bank's compliance expectations. Proactive licence maintenance and transparent communication with the banking relationship manager reduce – but do not eliminate – this risk.
How can a VASP onboard with an EMI?
A VASP seeking to onboard with an EMI should approach the engagement as a regulated entity presenting to a secondary regulator. The EMI will conduct enhanced due diligence covering the VASP's own authorisation, its AML programme, its beneficial ownership structure and its transaction monitoring infrastructure. A VASP that holds a recognised authorisation – a MiCA CASP, an MAS DPT service licence or an equivalent – and can present documented, operational compliance processes is substantially more likely to complete onboarding than a VASP relying on a registration that the EMI's home-jurisdiction regulator does not recognise. Legal counsel assists in preparing a pack that addresses the EMI's compliance checklist before the first approach.
What does client-money safeguarding require?
Client-money safeguarding – the obligation to hold client fiat funds separately from the firm's own funds and to protect them in the event of the firm's insolvency – is a regulated requirement in most leading jurisdictions. Under MiCA, EMT and certain CASP obligations impose specific safeguarding rules. Under the MAS Payment Services Act, stored-value and float-holding obligations apply to major payment institutions. The precise safeguarding mechanism – whether a segregated account, a trust arrangement or a guarantee product – varies by jurisdiction and licence category. Firms that hold client fiat balances as part of their on/off-ramp function should obtain jurisdiction-specific advice on whether their current arrangement satisfies the applicable safeguarding obligation.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – so your banking approach is built on a structure that holds under scrutiny. We work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications where recovery matters intersect with banking failures. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP licensing strategy, EMI onboarding compliance and cross-border regulatory mapping for digital-asset firms.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.