Fiat on/off-ramp banking sits at the intersection of crypto operations and the most risk-averse segment of traditional finance. For a virtual asset service provider (VASP) – a regulated business that exchanges, transfers or custodies digital assets on behalf of clients – the ability to convert between crypto and fiat is not a feature; it is the business. Lose your banking and you lose your product. With regulators across the EU under MiCA, Dubai under VARA, Singapore under the MAS Payment Services Act and the UK under the FCA tightening supervisory expectations simultaneously, the window between acceptable and unacceptable in the eyes of a correspondent bank has narrowed. This page maps the regulated basis, the onboarding process, the common structural errors and the cross-border realities that determine whether a VASP keeps its rails or loses them.
Why Fiat Rails Are a Legal Problem, Not Just a Banking One
Banks do not close crypto accounts arbitrarily. The decision is a compliance decision, driven by the bank's own regulatory obligations under anti-money-laundering rules that flow from the FATF Recommendations – in particular, FATF Recommendation 15, which brings virtual asset activity into the standard AML/CFT perimeter. A bank onboarding a VASP is, in effect, onboarding its counterparty's entire customer population. If the VASP's own KYC, transaction monitoring and Travel Rule controls are inadequate, the bank inherits the risk. Correspondent banks and domestic clearing institutions have concluded, repeatedly, that the reputational and regulatory cost of crypto exposure outweighs the revenue. The result is what practitioners call de-risking: account closures and onboarding refusals issued not on specific findings of wrongdoing but on category-level risk appetite.
For a VASP, this creates an asymmetry. The crypto regulatory licence – whether a CASP authorisation under MiCA, a VARA activity licence or a DPT service licence under the MAS Payment Services Act – authorises you to operate. It does not compel any bank to serve you. The licence and the banking relationship are legally distinct. Operators who conflate them lose both.
In our practice, we advise operators to treat the banking relationship as a separate regulatory project, parallel to the licence application and governed by its own documentation stack. The compliance memo you submit to a bank differs from the application you submit to a regulator – different audience, different risk questions, different evidence.
The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. If you are at the stage of choosing a jurisdiction or structuring your entity, the cross-border variables matter before you commit capital. For a scoped assessment of your banking position, contact OBOLUS at info@oboluslaw.com.
What Is Heightened Scrutiny in the Context of Fiat On/Off-Ramps?
Heightened scrutiny is not a formal legal category; it is the operating reality for any business whose primary function involves converting between fiat currency and digital assets. It means that standard commercial due diligence – a company search, a certificate of incorporation, a set of accounts – is insufficient. Banks and electronic money institutions (EMIs) – licensed entities that issue electronic money and provide payment services – apply an enhanced due diligence process that mirrors the enhanced customer due diligence obligations they carry under their own AML regimes.
In practice, heightened scrutiny produces a documentation demand that most crypto businesses underestimate at first approach. The bank or EMI will typically require: a detailed business model description; the full regulatory licence and the licence conditions; evidence of the operator's own KYC programme including its risk-based methodology; a sample of the transaction-monitoring rules in operation; the operator's Travel Rule compliance posture – meaning the mechanism by which originator and beneficiary data is passed with transfers above the applicable threshold; the beneficial ownership chain to the ultimate natural person; source-of-funds analysis for the initial capitalisation; and, increasingly, a third-party AML audit or a compliance counsel opinion letter.
The Travel Rule – the obligation, derived from FATF guidance and implemented in varying forms across MiCA, the MAS regime and other frameworks, to pass originator and beneficiary data with a virtual asset transfer – has become a specific sticking point. Banks want to see that the VASP has a functioning Travel Rule solution, not a policy document. Operators we advise routinely discover that their Travel Rule documentation is theoretically correct but operationally incomplete: the technology integration exists, but the compliance team cannot demonstrate a live data flow. That gap, discovered during bank due diligence, is a common reason for onboarding rejection.
The Regulatory Basis Across Jurisdictions: Where the Entity Sits Matters
The jurisdiction of the VASP's operating entity determines the regulatory anchor for the banking conversation. A CASP authorised under MiCA by a national competent authority in an EU member state carries a passportable licence, which in principle improves the bank's comfort level because the VASP sits inside a recognised, harmonised supervisory framework. An operator licensed by the FSRA within ADGM in Abu Dhabi, or by VARA in Dubai, operates under a well-regarded but non-EU framework. A BVI or Cayman entity registered under the BVI FSC or CIMA may hold a valid VASP registration but operate in a regime that many European correspondent banks treat with greater caution.
The practical consequence is this: the banking market available to a given VASP correlates strongly with the jurisdiction's status on FATF's own grey-list and blacklist monitoring, and on the perceptions of the banks' own compliance functions. We have seen operators obtain a licence efficiently in a mid-tier jurisdiction and then spend considerably longer – and at greater cost – seeking banking, because the time saved on licensing was not saved overall. The jurisdiction decision and the banking decision belong in the same analysis.
Singapore's MAS Payment Services Act creates a tiered licensing structure. An operator with a major payment institution licence under that regime is generally better positioned with Asian correspondent banks than an unlicensed entity. Hong Kong's SFC VATP licensing regime has a similar anchoring effect in the regional banking market. For UK-based operators, the FCA's cryptoasset registration under the Money Laundering Regulations provides a compliance signal, but the FCA's own concerns about the sector mean that de-risking by UK banks has not abated simply because a registration is in place.
How Do EMIs Differ from Banks for Crypto Onboarding?
For most VASPs, the practical fiat-rail solution is an EMI rather than a deposit-taking bank. EMIs sit in a different risk and business-model position: their core competency is payment processing, and their business development teams actively pursue fintech and digital-asset clients that banks decline. That does not mean EMI onboarding is easy. It means it is a different process with different failure modes.
EMIs in the EU operate under the Payment Services Directive regime, supervised by national competent authorities. An EMI licensed in Lithuania, regulated by the Bank of Lithuania under its MiCA transition framework, can passport across the EU. An EMI in the UK carries FCA e-money authorisation. The compliance bar for onboarding a VASP is, if anything, higher for EMIs than for banks in some respects: an EMI has fewer diversified revenues to absorb the cost of a compliance failure, so its own risk-appetite calculations are acute.
The common mistake at this stage is to treat EMI onboarding as a commercial negotiation rather than a regulatory submission. The operator sends a pitch deck and expects a term sheet. The EMI's compliance function – not its sales team – makes the decision. In our cross-border practice, we prepare a dedicated compliance information memorandum for each banking or EMI approach: a structured document that answers the compliance team's questions before they are asked, presents the regulatory programme in a form the EMI's own AML officer can file, and addresses the Travel Rule and transaction-monitoring architecture specifically. That document reduces the round-trip time on due diligence materially.
If a prior EMI application stalled or an account was closed, a second read of the structure can surface the reason and the route back. To map the licence, banking and payment-layer stack for your build, write to OBOLUS at info@oboluslaw.com.
What Are the Common Structural Errors That Kill Banking Relationships?
Account closures and onboarding rejections cluster around a small set of preventable structural errors. Understanding them before the first approach is the most efficient risk-management available.
Entity structure misalignment. The licensed entity, the entity that holds client funds and the entity that operates the platform are three different legal questions. Operators who run all functions through a single entity often find that the entity's regulatory classification does not map cleanly onto the bank's product categories. A holding company that also operates an exchange and custodies client assets presents a risk profile that a bank's compliance onboarding process is not designed to absorb. Separation of the operating, custody and payment functions – each into the correctly licensed entity – resolves this. We regularly advise on the structuring work before the first banking approach is made.
Inadequate client-money safeguarding documentation. Banks and EMIs that hold fiat on behalf of a VASP's clients need to understand whether those funds are client money – held separately, protected in the event of insolvency – or proprietary funds. The client-money safeguarding obligation, which applies to authorised payment institutions and EMIs under the applicable payment services rules, requires that client funds be held in a segregated account at an approved credit institution or invested in liquid low-risk assets. A VASP that cannot demonstrate its own safeguarding compliance – because it sits one level up in the payment chain – struggles to satisfy the EMI's own regulatory obligations.
Geographic mismatch. The entity is incorporated in one jurisdiction, the users are in another, the banking is sought in a third, and the operating team is in a fourth. Each of these facts generates a regulatory touch-point. Banks conduct their own analysis of the regulatory overlay in each jurisdiction. A VASP with users in the US but no FinCEN-registered Money Services Business status, or with European retail clients but no MiCA authorisation, will see those gaps identified and used as decline reasons.
Reactive rather than proactive compliance documentation. The operator waits for the bank to ask questions and then responds. Sophisticated onboarding processes run the other way: the operator provides a complete compliance package at first submission, demonstrating that it understands what the bank needs and can meet the standard without prompting. This signals operational maturity and reduces the bank's perception of residual risk.
Decision Matrix: Matching the Banking Structure to the Operator Profile
Not every VASP has the same banking problem. The structure that resolves one operator's issue will not resolve another's. The following decision guidance is qualitative; the specifics depend on facts that require legal advice.
Profile A – Licensed EU exchange seeking direct bank account. The operator holds a CASP authorisation under MiCA. It is seeking a relationship with a tier-one European bank for settlement of fiat client funds. The path involves demonstrating full MiCA compliance, an audited AML programme, Travel Rule implementation and, typically, a compliance counsel opinion confirming the regulatory status. Timeline to successful onboarding is typically measured in months, not weeks. Key risk: the bank's internal crypto policy may impose category-level restrictions regardless of the operator's compliance level.
Profile B – Offshore-licensed VASP seeking EMI rails for EU user base. The operator is licensed in a non-EU jurisdiction – BVI, Cayman or AIFC – and serves European users. It needs fiat payment infrastructure. The path is EMI onboarding in a jurisdiction whose regulatory framework the EMI recognises. The structural risk is that the absence of MiCA authorisation, combined with EU user exposure, may generate a regulatory gap that both the EMI and the VASP's own counsel need to address before onboarding proceeds. A MiCA transition plan or a referral arrangement through a licensed EU entity may be required.
Profile C – Payment institution seeking to add crypto services. A licensed payment institution – with existing banking and EMI relationships – wants to add VASP functionality. The path is a licence extension or parallel VASP registration, combined with a variation to the existing banking mandate. This is often the fastest route to integrated fiat/crypto infrastructure because the banking relationship pre-exists and the bank's compliance file already covers the operator. The key risk is that adding VASP services changes the bank's risk classification of the account.
Profile D – VASP that has lost banking and needs to rebuild. The operator's account was closed or its EMI terminated the relationship. The immediate need is replacement banking while the structural issue is resolved. The path typically involves a bridge arrangement through a specialist crypto-friendly EMI, concurrent with a review of the underlying structural or compliance deficiency that caused the closure. We have seen operators in this position rebuild banking in a matter of months once the structural issue is correctly identified.
Micro-Matter: Rebuilding Fiat Rails After Account Closure
In a recent matter, an exchange operator with users across multiple EU jurisdictions had its primary EMI relationship terminated with short notice. The closure notice cited generic AML concerns but offered no specific finding. We undertook a rapid review of the operator's compliance programme and identified two issues: the Travel Rule solution had been integrated but was not generating outbound data fields consistently, and the transaction-monitoring ruleset had not been updated following a change in the operator's user profile. We prepared a remediation plan and a revised compliance information memorandum, and approached three alternative EMIs concurrently. The operator obtained a replacement banking relationship within a matter of weeks, and the Travel Rule deficiency was resolved before the new EMI completed its own due diligence review. The original closure notice, once the structural picture was clear, reflected a technical gap rather than a substantive compliance failure.
The Cross-Border Compounding Effect: Where the Entity Sits vs. Where Users Are
The banking challenge for a digital-asset business is rarely confined to a single jurisdiction. A VASP incorporated in a jurisdiction with a well-regarded regulatory framework may serve users in markets where local law imposes its own payment-licensing obligations. An operator serving US persons without addressing FinCEN's Money Services Business requirements, or serving European consumers without a MiCA authorisation, creates a regulatory gap that any bank's correspondent compliance function will surface. The bank's problem is not the VASP's licence in its home jurisdiction; it is the unlicensed activity in the user's jurisdiction.
Allied counsel in the relevant jurisdiction is the standard approach for cross-border licensing questions: a local counsel in the US market for FinCEN and state money-transmitter licensing (MTL), a separate counsel in an EU member state for MiCA CASP onboarding. The coordination of those workstreams – ensuring the entity structure, the AML programme and the banking documentation tell a consistent story across jurisdictions – is where the value of integrated cross-border counsel lies.
Tax sits around this question too. The jurisdiction of the operating entity determines the tax treatment of the VASP's revenues, but the jurisdiction where users are located may impose withholding obligations or permanent-establishment risk if the operational footprint is substantial. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams – because a structure that solves the licensing question but creates a tax exposure, or obtains banking in a jurisdiction that then creates a regulatory filing obligation, has not solved the problem.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital-Asset Businesses – our core practice area covering fiat-rail access, EMI relationships and payment licensing
- Fiat On/Off-Ramp Banking: Practical Lessons for Boards – board-level analysis of the structural and tax decisions that determine banking access
- Transaction Monitoring Setup for Regulated Entities – the compliance infrastructure that underpins EMI onboarding and bank due diligence
FAQ
Why do banks close crypto company accounts?
Banks close crypto accounts primarily because of category-level risk appetite rather than specific findings of wrongdoing. Under AML rules derived from the FATF Recommendations, a bank onboarding a VASP inherits the compliance risk of the VASP's own customer base and transaction monitoring. Where the VASP's AML programme, Travel Rule implementation or regulatory status does not meet the bank's internal standard, the compliance cost of maintaining the relationship outweighs the commercial benefit. De-risking at the category level – closure of all crypto-related accounts regardless of individual compliance quality – remains common.
How can a VASP onboard with an EMI?
EMI onboarding requires treating the process as a regulatory submission, not a sales conversation. The EMI's compliance function – not its commercial team – makes the decision. A VASP should prepare a compliance information memorandum that covers its regulatory licence, AML/KYC methodology, transaction-monitoring architecture, Travel Rule solution, beneficial ownership structure and client-money safeguarding arrangements. Approaching the EMI with a complete compliance package at first submission reduces due-diligence round trips and signals operational maturity. The specific documentation requirements vary by EMI and jurisdiction.
What does client-money safeguarding require?
Client-money safeguarding, as required under payment services rules applicable to authorised payment institutions and EMIs, requires that funds held on behalf of clients are segregated from the firm's own funds and held either in a designated account at an approved credit institution or invested in liquid, low-risk instruments. The purpose is to protect client funds in the event of the institution's insolvency. VASPs whose fiat rails pass through an EMI need to understand where their clients' fiat funds sit in the safeguarding chain and whether any gap in that chain creates regulatory exposure for the EMI – and therefore an onboarding risk for the VASP.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – structuring banking and tax as one mandate rather than three disconnected workstreams. To discuss your banking and payment-layer situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialist in VASP regulatory programmes, EMI onboarding documentation and cross-border AML compliance architecture.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.