Hands holding euro banknotes and a wallet, opening a crypto bank account for a VASP company in 2026
Guides: Banking & Operations

How to Open a Bank Account for a Crypto/VASP Company in 2026

A crypto licence does not buy you a bank account. This guide explains why banks de-risk VASPs, how your licence affects onboarding, the difference between a bank, an EMI, and a payment institution, how segregated client accounts work, the documents banks demand, and realistic timelines for getting a crypto bank account live in 2026.

Reading time~10 minutes
Last updatedJune 2026
CategoryBanking & Operations

Meet Dr. Marcus Hartmann

Dr. Marcus Hartmann, Senior Crypto Licensing Advisor
Dr. Marcus Hartmann
Senior Licensing Advisor · Zug, Switzerland
LL.M. International Financial Law · Dr. iur. · Zurich Bar

Dr. Marcus Hartmann has spent over two decades at the intersection of financial law and emerging technology. Based in Zug, Switzerland's Crypto Valley, he has guided exchanges, custodians, and institutional investors through VASP and CASP licensing and, just as often, through the harder problem that follows: securing and keeping the bank accounts a regulated crypto business needs to operate.

He has built banking strategies for clients across the EU, the United Kingdom, Switzerland, the Gulf, and Asia, coordinating operating, safeguarding, and inbound-deposit relationships with banks, e-money institutions, and specialist crypto-friendly partners across more than 60 jurisdictions.

22 years in financial services regulation
400+ crypto licensing mandates across 60+ jurisdictions
Certified AML Officer (ACAMS), FINMA-registered
Fluent in English, German, and French
View Full Profile →
Quick Answer · Crypto Bank Account for a VASP

To open a bank account for a crypto/VASP company, first hold a recognised licence, then approach banks through a warm introduction with a complete file: a corporate and UBO chart, an AML programme with a named MLRO, source-of-funds evidence, and named analytics and Travel Rule providers. Use a bank for safeguarding and an EMI as the inbound rail. Budget 4 to 7 months.

Key Takeaways
  • A crypto licence is a prerequisite for banking, not a guarantee; unlicensed VASPs are declined automatically by Tier-1 banks and processors
  • Banks de-risk crypto because of correspondent banking exposure, Basel III capital charges, and the high AML alert volume a single VASP generates
  • A bank can hold MiCA safeguarding deposits and issue correspondent letters; an EMI is a fast inbound rail but cannot replace the bank for safeguarding
  • Client funds must sit in segregated, named, ring-fenced accounts kept separate from the company's operating money
  • Plan 4 to 7 months to a funded bank account, expect to apply to 8 to 15 institutions, and run 4 to 6 accounts for resilience

The Hardest Part Is Not the Licence

Most founders treat authorisation as the finish line. In practice, the hardest part of running a regulated crypto-asset business is not getting the licence. It is opening, and then keeping, the operating, safeguarding, and inbound-deposit accounts at institutions that will not de-risk the firm twelve months later. A crypto bank account for a VASP is won through preparation, not paperwork alone.

This guide walks through the full path: why banks are wary of crypto, why your licence has to come first, how a bank differs from an e-money institution and a payment institution, how segregated client accounts work, exactly what documents a bank wants to see, and a realistic step-by-step timeline. If you have not yet secured authorisation, start with our guide on how to get a crypto licence, then come back here, because banking should be planned alongside the licence, not after it.

For a working list of the institution categories that actively onboard regulated crypto firms, pair this guide with our crypto-friendly banks guide. Together they cover the strategy and the targets.

4–7 mo
Bank: Pitch to Funded Account
4–8 wk
EMI Inbound Rail Live
8–15
Banks Applied To (Typical)
4–6
Accounts For Resilience
€150k
MiCA Class 3 Capital Floor
€5–50m
Monthly Volume Sweet Spot

Indicative market figures for EEA crypto-asset firms in 2026. Capital floor from MiCA Regulation (EU) 2023/1114; timelines and volume bands reflect prevailing banking practice and vary by institution.

Why Banks De-Risk Crypto and VASP Companies

Understanding why banks hesitate is the first step to changing the answer. De-banking is rarely about a VASP doing something wrong. It is usually about the bank's risk appetite changing, often for reasons outside the client's control. Three structural pressures drive it.

Correspondent banking exposure. Most banks rely on larger correspondent partners to settle cross-border payments. When a single correspondent line decides crypto is too risky, the smaller bank can be forced to drop its entire crypto portfolio overnight to keep that line open. This happened across the Baltics in 2018 and 2019 and again at several US mid-tier banks in 2023.

Capital charges. Under the Basel framework, operational accounts linked to client crypto proceeds attract conservative risk weights, which raises the capital a bank must hold against the deposit. A low-margin crypto client can therefore consume more balance-sheet capacity than a far larger conventional one.

AML bandwidth. A single crypto-asset service provider can generate several times the suspicious-activity alert volume of an equivalent non-crypto business. For an understaffed compliance team, one VASP can absorb the monitoring capacity of many ordinary clients. Our explainer on AML and KYC shows where that alert load comes from.

The takeaway is that the bank is managing its own supervisory and commercial risk. Your job as a VASP is to make yourself the lowest-friction crypto client a bank could accept, so the risk-appetite calculation lands in your favour.

Why a Licence Comes First, and Why Its Brand Matters

There is a hard sequencing rule in crypto banking: the licence comes before the account. Tier-1 banks and major payment processors will not open operating or safeguarding accounts for unlicensed crypto businesses, full stop. A valid VASP or CASP licence is a prerequisite, not a differentiator. If you are still defining your model, our overview of the VASP licence sets out what authorisation actually involves.

Just as important, the brand of the licence matters more than its type. A crypto-asset service provider authorisation from a respected EU regulator opens doors that a legacy registration from a lighter-touch jurisdiction does not. Bankers read the issuing regulator as a proxy for supervisory quality, so where you license shapes who will bank you.

This effect is sharpening in 2026. With the EU's older VASP registration regimes sunsetting as MiCA takes hold, banks increasingly treat pre-MiCA registrations as expiring credentials and ask pointed questions about a firm's transition plan. Choosing a durable, well-regarded authorisation is now part of your banking strategy, not just your compliance one.

"We tell clients to choose their licence with the bank in mind. The same exchange model authorised by a top-tier EU regulator and by a marginal offshore registry will get opposite answers from the same bank. The cheapest licence often becomes the most expensive once you cannot open an account behind it."

Dr. Marcus Hartmann, Senior Licensing Advisor

Bank vs EMI vs Payment Institution

Crypto banking access is not one product. A resilient VASP combines several account types, each doing a different job. Confusing them is one of the most common and costly mistakes founders make, because an e-money institution and a credit institution are not interchangeable.

A bank, or credit institution, can hold client safeguarding deposits as bank money, issue correspondent banking sponsor letters, and extend treasury and FX lines. It is the slowest to onboard but the strongest relationship. An e-money institution (EMI) is much faster and excellent at issuing virtual IBANs for inbound client deposits and clearing SEPA payments, but it cannot hold MiCA-grade safeguarding deposits the way a bank can, cannot issue correspondent letters, and offers no treasury lines. A payment or specialist institution typically focuses on FX and settlement. Our hub on crypto banking goes deeper on how these licences themselves work.

The practical rule: use an EMI as the rail for inbound client deposits, never as the only banking layer. Safeguarding belongs at a bank.

Capability Bank (Credit Institution) EMI Payment / Specialist Institution
Hold MiCA safeguarding deposits Yes No Limited / varies
Virtual IBANs for client inbound Yes Yes Often
Correspondent sponsor letters Yes No No
FX / treasury lines Yes No FX focus
Typical onboarding time 4–7 months 4–8 weeks 4–10 weeks
Best used as Operating + safeguarding core Inbound deposit rail FX / settlement layer

Capabilities reflect the functional limits of each institution type under EU PSD2 and MiCA. Specifics depend on the individual provider and jurisdiction.

Why this matters: a single-bank setup is one supervisor letter away from operational shutdown. A robust architecture runs 4 to 6 institutions: a primary operating account, a backup in a second jurisdiction, a ring-fenced safeguarding account, an EMI inbound rail, and an FX or custody provider. Build redundancy from day one, not after the first de-banking scare.

◆ Need Help?

Not sure which mix of bank, EMI, and FX provider fits your model? Get a free 30-minute consultation. We will map a banking architecture to your licence, markets, and volumes.

Get Free Consultation →

How Segregated Client Accounts Work

If your VASP touches client money, segregation is not optional. A segregated client account is a named, ring-fenced account that holds customer funds entirely separate from the company's own operating cash. Under MiCA, crypto-asset service providers must safeguard client funds in exactly this way, and the requirement is one of the first things a bank checks before opening an account behind your licence.

In practice, a safeguarding account is held at a credit institution, distinct from your day-to-day operating bank, and is treated as the customers' property rather than the company's. This is precisely the function an EMI cannot perform under MiCA, which is why the safeguarding layer almost always sits at a bank even when the inbound rail runs through an e-money institution.

The detailed rules show the same pattern worldwide. When Pakistan re-opened banking access for licensed VASPs in 2026, for example, regulators required separate client money accounts that are non-remunerative, prohibit cash deposits and withdrawals, cannot be used as collateral, and must never commingle client and company funds. The labels change by jurisdiction, but the principle, that client money is protected and visibly separate, is now a global baseline.

Feature Operating Account Segregated Client / Safeguarding Account
Whose money The company's The clients'
Held at Operating bank (or EMI rail) Separate credit institution, ring-fenced
Commingling allowed n/a Prohibited
Use as collateral Permitted Prohibited
Typical interest May be remunerative Often non-remunerative

Generalised from MiCA safeguarding rules and comparable national client-money regimes. Exact conditions are set by your licensing jurisdiction.

The Documents Banks Require

Onboarding diligence at a crypto-friendly bank looks more like investment-banking due diligence than retail account opening. Expect six to ten weeks of preparation before you even file. The stronger and more complete your pack, the faster the committee can say yes. Banks consistently ask for the following.

Corporate and ownership

A cover memo mapping your services to your licence, a corporate structure diagram showing the full ultimate beneficial owner chain with any nominees disclosed, and audited financial statements. Undisclosed offshore entities in the structure are a fast route to decline.

AML programme and the MLRO

A detailed, crypto-specific AML programme covering transaction monitoring and typologies, plus governance: a regulator-approved Money Laundering Reporting Officer, an independent compliance officer, and resident directors where the licence requires them. Banks inherit their clients' AML risk, so they need to see that you will catch and report suspicious activity before it reaches their books. Our AML and KYC service builds this end to end.

Vendors and source of funds

Named contracts with a blockchain analytics provider and a Travel Rule provider, not in-house promises. A twelve-month customer-geography and volume forecast. And source-of-funds evidence: bank statements and records proving where operating capital came from, confirming it is not tied to undisclosed entities or sanctioned parties.

From Our Practice

In our banking work across more than 60 jurisdictions, the single biggest predictor of a smooth onboarding is not the business model. It is whether the firm walks in with a complete, self-consistent file. When the corporate chart, the AML programme, the named vendors, and the source-of-funds evidence all tell the same story, financial-crime committees move quickly. When a UBO is buried in an offshore trust or the AML policy is a generic template, the same committee stalls for months.

We also push every client toward redundancy before they need it. The clients who sail through a de-banking event are the ones who already held a backup operating account in a second jurisdiction and an EMI inbound rail, so a single supervisor letter never freezes their operations. Building that architecture during licensing, rather than after the first scare, is consistently the difference between a contained incident and an existential one.

The Account-Opening Process, Step by Step

From first pitch to a funded operating account, a Tier-1 EEA bank typically takes four to seven months, with diligence alone running eight to sixteen weeks. The five stages below describe the path. Warm introductions consistently beat cold applications, which banks tend to deprioritise. Need help with the introductions and the file? Talk to our team.

1
Weeks 1–2 · Prepare & approach
Licence in hand, warm introduction made
Confirm your authorisation, assemble the diligence pack, and approach target banks through a warm introduction rather than a cold form, which banks routinely deprioritise.
2
Weeks 3–6 · Submit
File submission and gap identification
Submit the full file. The bank reviews the corporate chart, AML programme, vendors, and source of funds, then comes back with gaps to close before escalation.
3
Weeks 6–12 · Diligence
Financial-crime committee review
A financial-crime committee assesses the file, usually with a video or on-site diligence session covering governance, monitoring, and customer base.
4
Weeks 12–18 · Approve
Credit committee and account package
The credit committee signs off and issues the account-opening package, setting deposit, volume, and reporting conditions for the relationship.
5
Weeks 18–24 · Onboard & maintain
IBAN issuance, safeguarding, and reviews
Operational onboarding issues IBANs, sets up the segregated safeguarding account, and tests mandates. Then keep it: quarterly reviews, annual AML refresh, and self-reported hits.

Indicative timeline for a Tier-1 EEA bank. EMI inbound rails complete far faster, typically in 4 to 8 weeks.

Crypto / VASP Bank Accounts: Common Questions

In practice, no. Tier-1 banks and major payment processors will not open operating or safeguarding accounts for unlicensed crypto businesses. A valid VASP or CASP licence is a prerequisite, not a differentiator. Without it, even compliant firms face automatic decline at the onboarding stage.
Banks de-risk crypto clients for three structural reasons: correspondent banking partners can withdraw support overnight, Basel III capital charges on crypto-linked deposits are high, and a single VASP can generate several times the AML alert volume of a comparable non-crypto client. De-banking usually reflects a change in the bank's risk appetite, not wrongdoing.
Expect roughly 4 to 7 months from first outreach to a fully funded operating account at a Tier-1 EEA bank. Diligence alone runs 8 to 16 weeks. An EMI inbound rail can be live in 4 to 8 weeks, but an EMI cannot replace a bank for client safeguarding.
A bank (credit institution) can hold client safeguarding deposits as bank money and issue correspondent letters. An EMI issues virtual IBANs and clears SEPA payments but cannot hold MiCA-grade safeguarding deposits. A payment or specialist institution typically handles FX and settlement. Most VASPs use several together.
A segregated client account is a named, ring-fenced account that holds customer funds separately from the VASP's own operating money. Under MiCA, client funds must be safeguarded in such accounts. Typically they are non-remunerative, cannot be used as collateral, and prohibit commingling with company funds.
Banks expect a cover memo mapping services to the licence, a full corporate and UBO structure chart, audited financials, a detailed AML programme with crypto typologies, named blockchain analytics and Travel Rule provider contracts, a customer geography and volume forecast, and bank statements evidencing source of capital.
Banks inherit the AML risk of their VASP clients, so they verify that the firm has its own controls. A regulator-approved Money Laundering Reporting Officer and a written, crypto-specific AML programme with transaction monitoring show the bank that suspicious activity will be detected and reported before it reaches the bank's own books.
No. An EMI is an excellent inbound rail for client deposits through virtual IBANs and SEPA clearing, and it reduces concentration risk. But EMIs cannot hold MiCA safeguarding deposits the way a credit institution can, issue correspondent banking letters, or provide treasury lines. Use an EMI alongside a bank, not instead of one.
Above the MiCA Class 3 floor of EUR 150,000, banks like to see roughly 18 to 24 months of operating runway plus prudential capital. For a mid-sized CASP this often means around EUR 1.5 to 3 million held at the bank before the file is treated as low risk, though figures vary by institution.
Most VASPs apply to between 8 and 15 institutions before securing a stable relationship. A robust setup uses 4 to 6 accounts: a primary operating account, a backup in a second jurisdiction, a ring-fenced safeguarding account, an EMI inbound rail, and an FX or custody provider. Single-bank reliance is a major operational risk.
Common fast-decline triggers are a global retail customer base with no jurisdiction limits, supporting privacy coins or mixers, a UBO in a FATF grey-list or EU high-risk jurisdiction, no named blockchain analytics or Travel Rule provider, and offshore intermediary structures with undisclosed nominee directors.
Yes. The issuing regulator matters more than the licence type. A MiCA CASP authorisation from a respected EU regulator opens doors that a legacy registration does not. With EU VASP regimes sunsetting in 2025 and 2026, banks increasingly treat pre-MiCA registrations as expiring credentials.
Treat banking as a continuous programme. Hold quarterly business reviews, refresh your AML and source-of-funds pack annually even if unprompted, self-report AML hits before the bank finds them, and respond to information requests within tight timelines. Banks usually exit quietly, so proactive disclosure preserves the relationship.
Source of funds is documented evidence of where the company's and shareholders' money comes from, shown through bank statements, financials, and corporate records. Banks require it to confirm that operating capital is not linked to undisclosed offshore entities, money laundering, or sanctioned parties before they accept the deposit.

Sources & Official References

MH
Senior Licensing Advisor · LL.M. International Financial Law
22 years in financial services regulation. Advised 400+ crypto licensing mandates across 60+ jurisdictions. Based in Zug, Switzerland.
Free Consultation

Get Your Crypto Business Banked, Not De-Banked

Share your licence, business model, and target markets, and we will map the banking architecture you need, prepare the file banks expect, and open the right introductions. No obligation.

  • 🇨🇭 Swiss-registered firm, Zug
  • ⚡ Response within 24 hours
  • 🔒 Strictly confidential
  • ✓ 80+ jurisdictions covered

Confidential · No obligation · No spam