Meet Dr. Marcus Hartmann
Dr. Marcus Hartmann has spent over two decades at the intersection of financial law and emerging technology. Based in Zug, Switzerland's Crypto Valley, he has guided exchanges, custodians, and institutional investors through VASP and CASP licensing and, just as often, through the harder problem that follows: securing and keeping the bank accounts a regulated crypto business needs to operate.
He has built banking strategies for clients across the EU, the United Kingdom, Switzerland, the Gulf, and Asia, coordinating operating, safeguarding, and inbound-deposit relationships with banks, e-money institutions, and specialist crypto-friendly partners across more than 60 jurisdictions.
To open a bank account for a crypto/VASP company, first hold a recognised licence, then approach banks through a warm introduction with a complete file: a corporate and UBO chart, an AML programme with a named MLRO, source-of-funds evidence, and named analytics and Travel Rule providers. Use a bank for safeguarding and an EMI as the inbound rail. Budget 4 to 7 months.
- A crypto licence is a prerequisite for banking, not a guarantee; unlicensed VASPs are declined automatically by Tier-1 banks and processors
- Banks de-risk crypto because of correspondent banking exposure, Basel III capital charges, and the high AML alert volume a single VASP generates
- A bank can hold MiCA safeguarding deposits and issue correspondent letters; an EMI is a fast inbound rail but cannot replace the bank for safeguarding
- Client funds must sit in segregated, named, ring-fenced accounts kept separate from the company's operating money
- Plan 4 to 7 months to a funded bank account, expect to apply to 8 to 15 institutions, and run 4 to 6 accounts for resilience
The Hardest Part Is Not the Licence
Most founders treat authorisation as the finish line. In practice, the hardest part of running a regulated crypto-asset business is not getting the licence. It is opening, and then keeping, the operating, safeguarding, and inbound-deposit accounts at institutions that will not de-risk the firm twelve months later. A crypto bank account for a VASP is won through preparation, not paperwork alone.
This guide walks through the full path: why banks are wary of crypto, why your licence has to come first, how a bank differs from an e-money institution and a payment institution, how segregated client accounts work, exactly what documents a bank wants to see, and a realistic step-by-step timeline. If you have not yet secured authorisation, start with our guide on how to get a crypto licence, then come back here, because banking should be planned alongside the licence, not after it.
For a working list of the institution categories that actively onboard regulated crypto firms, pair this guide with our crypto-friendly banks guide. Together they cover the strategy and the targets.
Indicative market figures for EEA crypto-asset firms in 2026. Capital floor from MiCA Regulation (EU) 2023/1114; timelines and volume bands reflect prevailing banking practice and vary by institution.
Why Banks De-Risk Crypto and VASP Companies
Understanding why banks hesitate is the first step to changing the answer. De-banking is rarely about a VASP doing something wrong. It is usually about the bank's risk appetite changing, often for reasons outside the client's control. Three structural pressures drive it.
Correspondent banking exposure. Most banks rely on larger correspondent partners to settle cross-border payments. When a single correspondent line decides crypto is too risky, the smaller bank can be forced to drop its entire crypto portfolio overnight to keep that line open. This happened across the Baltics in 2018 and 2019 and again at several US mid-tier banks in 2023.
Capital charges. Under the Basel framework, operational accounts linked to client crypto proceeds attract conservative risk weights, which raises the capital a bank must hold against the deposit. A low-margin crypto client can therefore consume more balance-sheet capacity than a far larger conventional one.
AML bandwidth. A single crypto-asset service provider can generate several times the suspicious-activity alert volume of an equivalent non-crypto business. For an understaffed compliance team, one VASP can absorb the monitoring capacity of many ordinary clients. Our explainer on AML and KYC shows where that alert load comes from.
The takeaway is that the bank is managing its own supervisory and commercial risk. Your job as a VASP is to make yourself the lowest-friction crypto client a bank could accept, so the risk-appetite calculation lands in your favour.
Why a Licence Comes First, and Why Its Brand Matters
There is a hard sequencing rule in crypto banking: the licence comes before the account. Tier-1 banks and major payment processors will not open operating or safeguarding accounts for unlicensed crypto businesses, full stop. A valid VASP or CASP licence is a prerequisite, not a differentiator. If you are still defining your model, our overview of the VASP licence sets out what authorisation actually involves.
Just as important, the brand of the licence matters more than its type. A crypto-asset service provider authorisation from a respected EU regulator opens doors that a legacy registration from a lighter-touch jurisdiction does not. Bankers read the issuing regulator as a proxy for supervisory quality, so where you license shapes who will bank you.
This effect is sharpening in 2026. With the EU's older VASP registration regimes sunsetting as MiCA takes hold, banks increasingly treat pre-MiCA registrations as expiring credentials and ask pointed questions about a firm's transition plan. Choosing a durable, well-regarded authorisation is now part of your banking strategy, not just your compliance one.
"We tell clients to choose their licence with the bank in mind. The same exchange model authorised by a top-tier EU regulator and by a marginal offshore registry will get opposite answers from the same bank. The cheapest licence often becomes the most expensive once you cannot open an account behind it."
Dr. Marcus Hartmann, Senior Licensing Advisor
Bank vs EMI vs Payment Institution
Crypto banking access is not one product. A resilient VASP combines several account types, each doing a different job. Confusing them is one of the most common and costly mistakes founders make, because an e-money institution and a credit institution are not interchangeable.
A bank, or credit institution, can hold client safeguarding deposits as bank money, issue correspondent banking sponsor letters, and extend treasury and FX lines. It is the slowest to onboard but the strongest relationship. An e-money institution (EMI) is much faster and excellent at issuing virtual IBANs for inbound client deposits and clearing SEPA payments, but it cannot hold MiCA-grade safeguarding deposits the way a bank can, cannot issue correspondent letters, and offers no treasury lines. A payment or specialist institution typically focuses on FX and settlement. Our hub on crypto banking goes deeper on how these licences themselves work.
The practical rule: use an EMI as the rail for inbound client deposits, never as the only banking layer. Safeguarding belongs at a bank.
| Capability | Bank (Credit Institution) | EMI | Payment / Specialist Institution |
|---|---|---|---|
| Hold MiCA safeguarding deposits | Yes | No | Limited / varies |
| Virtual IBANs for client inbound | Yes | Yes | Often |
| Correspondent sponsor letters | Yes | No | No |
| FX / treasury lines | Yes | No | FX focus |
| Typical onboarding time | 4–7 months | 4–8 weeks | 4–10 weeks |
| Best used as | Operating + safeguarding core | Inbound deposit rail | FX / settlement layer |
Capabilities reflect the functional limits of each institution type under EU PSD2 and MiCA. Specifics depend on the individual provider and jurisdiction.
Why this matters: a single-bank setup is one supervisor letter away from operational shutdown. A robust architecture runs 4 to 6 institutions: a primary operating account, a backup in a second jurisdiction, a ring-fenced safeguarding account, an EMI inbound rail, and an FX or custody provider. Build redundancy from day one, not after the first de-banking scare.
Not sure which mix of bank, EMI, and FX provider fits your model? Get a free 30-minute consultation. We will map a banking architecture to your licence, markets, and volumes.
Get Free Consultation →How Segregated Client Accounts Work
If your VASP touches client money, segregation is not optional. A segregated client account is a named, ring-fenced account that holds customer funds entirely separate from the company's own operating cash. Under MiCA, crypto-asset service providers must safeguard client funds in exactly this way, and the requirement is one of the first things a bank checks before opening an account behind your licence.
In practice, a safeguarding account is held at a credit institution, distinct from your day-to-day operating bank, and is treated as the customers' property rather than the company's. This is precisely the function an EMI cannot perform under MiCA, which is why the safeguarding layer almost always sits at a bank even when the inbound rail runs through an e-money institution.
The detailed rules show the same pattern worldwide. When Pakistan re-opened banking access for licensed VASPs in 2026, for example, regulators required separate client money accounts that are non-remunerative, prohibit cash deposits and withdrawals, cannot be used as collateral, and must never commingle client and company funds. The labels change by jurisdiction, but the principle, that client money is protected and visibly separate, is now a global baseline.
| Feature | Operating Account | Segregated Client / Safeguarding Account |
|---|---|---|
| Whose money | The company's | The clients' |
| Held at | Operating bank (or EMI rail) | Separate credit institution, ring-fenced |
| Commingling allowed | n/a | Prohibited |
| Use as collateral | Permitted | Prohibited |
| Typical interest | May be remunerative | Often non-remunerative |
Generalised from MiCA safeguarding rules and comparable national client-money regimes. Exact conditions are set by your licensing jurisdiction.
The Documents Banks Require
Onboarding diligence at a crypto-friendly bank looks more like investment-banking due diligence than retail account opening. Expect six to ten weeks of preparation before you even file. The stronger and more complete your pack, the faster the committee can say yes. Banks consistently ask for the following.
Corporate and ownership
A cover memo mapping your services to your licence, a corporate structure diagram showing the full ultimate beneficial owner chain with any nominees disclosed, and audited financial statements. Undisclosed offshore entities in the structure are a fast route to decline.
AML programme and the MLRO
A detailed, crypto-specific AML programme covering transaction monitoring and typologies, plus governance: a regulator-approved Money Laundering Reporting Officer, an independent compliance officer, and resident directors where the licence requires them. Banks inherit their clients' AML risk, so they need to see that you will catch and report suspicious activity before it reaches their books. Our AML and KYC service builds this end to end.
Vendors and source of funds
Named contracts with a blockchain analytics provider and a Travel Rule provider, not in-house promises. A twelve-month customer-geography and volume forecast. And source-of-funds evidence: bank statements and records proving where operating capital came from, confirming it is not tied to undisclosed entities or sanctioned parties.
In our banking work across more than 60 jurisdictions, the single biggest predictor of a smooth onboarding is not the business model. It is whether the firm walks in with a complete, self-consistent file. When the corporate chart, the AML programme, the named vendors, and the source-of-funds evidence all tell the same story, financial-crime committees move quickly. When a UBO is buried in an offshore trust or the AML policy is a generic template, the same committee stalls for months.
We also push every client toward redundancy before they need it. The clients who sail through a de-banking event are the ones who already held a backup operating account in a second jurisdiction and an EMI inbound rail, so a single supervisor letter never freezes their operations. Building that architecture during licensing, rather than after the first scare, is consistently the difference between a contained incident and an existential one.
The Account-Opening Process, Step by Step
From first pitch to a funded operating account, a Tier-1 EEA bank typically takes four to seven months, with diligence alone running eight to sixteen weeks. The five stages below describe the path. Warm introductions consistently beat cold applications, which banks tend to deprioritise. Need help with the introductions and the file? Talk to our team.
Indicative timeline for a Tier-1 EEA bank. EMI inbound rails complete far faster, typically in 4 to 8 weeks.
Crypto / VASP Bank Accounts: Common Questions
Sources & Official References
- EUR-Lex: Regulation (EU) 2023/1114 (MiCA), including client-fund safeguarding under Article 75
- EBA: Anti-Money Laundering and Countering the Financing of Terrorism policy and guidelines
- EBA: Payment services and electronic money (PSD2, EMI safeguarding)
- FINMA: FinTech and crypto authorisation, banking and AML supervision in Switzerland
- FATF: Virtual assets and VASP standards (AML/CFT)
- BIS / Basel Committee: Prudential treatment of cryptoasset exposures
- State Bank of Pakistan: 2026 framework permitting bank accounts and client money accounts for licensed VASPs