September 2026
5 Mins

Why Crypto and Payment Businesses Get Rejected by Banks (2026)

Why Crypto and Payment Businesses Get Rejected by Banks

At a glance 

1.  Most refusals are de-risking, which the European Banking Authority defines as refusing or terminating a relationship with a customer or category of customers associated with higher money laundering or terrorist financing risk.

2.  EBA Guidelines EBA/GL/2023/04 require an institution to consider and reject all reasonable mitigating measures before refusing or terminating, and to document the decision and its reason.

3.  The EBA has stated that de-risking whole categories of customers without considering individual risk profiles may be unwarranted and a sign of ineffective risk management.

4.  Since 30 December 2024, amended Guidelines EBA/GL/2023/03 give institutions specific guidance on the risks to weigh when dealing with crypto-asset service providers, which is why licence status now drives banking outcomes.

5.  There is no right to a business bank account in EU law. The right of access to a payment account with basic features under Directive 2014/92/EU applies to consumers, not to companies.

A bank account is usually the first thing a fintech or crypto business discovers it cannot get, and the last thing anyone told it to plan for. The application is declined without a reason, or the account is opened and closed six months later. The founder reads it as a commercial decision, or as prejudice against the sector, and applies to the next institution with the same file.

In most cases the cause is neither commercial nor prejudicial. It is structural, it was created months earlier, and it is visible in the application documents. This article sets out what the rules actually require of an institution before it refuses you, which risk factors decide the outcome, why a correctly incorporated company still gets declined, and what to do if you have already been refused.

What de-risking is, and why it sits behind most refusals

De-risking is a decision by a credit or financial institution to refuse to enter into, or to terminate, a business relationship with an individual customer or a category of customers associated with higher money laundering or terrorist financing risk, or to refuse to carry out higher risk transactions. The European Banking Authority set out this definition in its January 2022 Opinion on de-risking and carried it into Guidelines EBA/GL/2023/04.

Institutions de-risk for three reasons the EBA has identified. The money laundering, terrorist financing or reputational risk exceeds their appetite. They lack the knowledge or expertise to assess the risk attached to a specific business model. Or the expected cost of compliance outweighs the anticipated profit from the relationship.

Only the first of those is about you. The second and third are about the institution, and they explain why the same file can be declined by one bank and accepted by another without anything changing on your side. An institution with no crypto-competent analyst will not build one for a single applicant. This is why shopping the same application around rarely works, and why the institution's own capability matters as much as your risk profile.

What an institution must do before it refuses you

EBA Guidelines EBA/GL/2023/04, published 31 March 2023, set out the policies, procedures and controls institutions should have in place when providing access to financial services, and the steps they should take when considering whether to refuse or terminate a relationship on money laundering, terrorist financing or AML compliance grounds. They complement the separate Guidelines on ML/TF risk factors.

The guidelines are addressed to institutions, not to customers, but they are public, and they describe a process that produces a documented decision. Knowing what that process requires tells you what to ask for.

What the guidelines require What it means in practice
Policies must not result in blanket refusal or termination of entire categories of customers assessed as higher risk “We do not bank crypto” is not, on its own, a position the guidelines support
Risk-sensitive policies must set out the grounds on which a relationship may be rejected or terminated, and all mitigating options to be considered first There is a defined ground behind your refusal, and it exists in writing
Before rejecting or terminating, the institution should satisfy itself it has considered and rejected all mitigating measures that could reasonably apply Additional controls, restricted products or enhanced monitoring should be weighed before outright refusal
Decisions must be documented with the reason, and made available to the competent authority on request The decision is recorded and supervisable, even where it is not explained to you
Decisions must be proportionate and consistent with non-discrimination principles Category-level treatment without individual assessment is exposed
On communicating a refusal or termination, the institution must advise the person of the right to contact the relevant competent authority or alternative dispute resolution body, and provide contact details You are entitled to be told where to complain, and this is the most usable lever available to a rejected applicant

What no institution owes you

It is worth being precise here, because a great deal of published commentary is not. EU law does create a right of access to a payment account with basic features. That right sits in Directive 2014/92/EU, the Payment Accounts Directive, and it applies to consumers. It does not extend to companies.

A business therefore has no entitlement to an account. What it has is a set of procedural expectations on the institution: that the decision be individual rather than categorical, that mitigations be considered, that the reason be documented, and that a complaint route be disclosed. Those are real and worth using. They are not a right to be onboarded.

The practical consequence is that the route to banking is not asserting a right. It is making the file approvable, which means removing the specific risk factors that cause an analyst to decline rather than escalate.

The risk factors that decide the outcome

EBA Guidelines EBA/GL/2021/02 set out the money laundering and terrorist financing risk factors institutions should consider when assessing individual business relationships. Amending Guidelines EBA/GL/2023/03 extended them to crypto-asset service providers and added guidance for other credit and financial institutions on the risks to consider when entering business relationships with CASPs or otherwise becoming exposed to crypto-assets. They apply from 30 December 2024.

The guidelines group risk factors into four categories. An application is assessed against all four at once, and a serious problem in any one of them can decide the outcome on its own.

Risk factor category What is being examined
Customer Ownership and control, complexity of the group, beneficial owners and their jurisdictions, the standing and experience of directors and the compliance function, source of wealth and source of funds
Product, service and transaction What the business actually does, expected volumes and values, whether flows are one way or reciprocal, exposure to cash or to anonymous instruments, and whether the product mix matches the licence held
Delivery channel Whether onboarding is face to face or remote, reliance on intermediaries or agents, use of third-party introducers, and how customer due diligence is performed on your own customers
Geographic Countries of incorporation, operation, customers and counterparties, weighed against the deficiencies identified in each and the institution's own country risk framework

For crypto-asset service providers specifically, the amended guidelines note that risk can be increased by the use of innovative technologies, by instant transfers of crypto-assets across the world, and by services that contain privacy-enhancing features. An institution reading your application is looking for whether you have recognised those and built controls against them, not for whether they are present.

Why a correctly incorporated company still gets declined

Three things have to agree: the corporate structure, the licence or registration held, and the expected flow of funds. Most refusals are a disagreement between two of them.

The commonest pattern is a structure built for tax or for investor optics that does not support the licensing path, presented to an institution that reads the mismatch as either a control weakness or an attempt at opacity. A holding company in one jurisdiction, an operating company in another, a licence applied for in a third, and customer flows arriving from a fourth is a defensible arrangement. It is also four separate explanations an analyst has to accept, and each one is a point at which the file can be declined instead of escalated.

The second pattern is a licence that does not cover the activity described. A registration permitting exchange services does not support an application describing custody, payouts to third parties and stored client balances. The institution is not obliged to reconcile the two, and generally will not.

The third is a flow description that cannot be monitored. Where an institution cannot see how it would detect an anomaly in your expected activity, it cannot hold the relationship within its own supervisory obligations, and the mitigation step in EBA/GL/2023/04 has no available answer.

What changed with MiCA, and why licence status now decides banking

Before MiCA, an institution weighing a crypto client was making a judgement about an unregulated or nationally registered counterparty. That judgement has now largely been made for it.

The MiCA transitional period closed across the EU on 1 July 2026. In its statement of 17 April 2026, ESMA confirmed that after that date any entity providing crypto-asset services to EU clients without a MiCA licence is in breach of EU law and must cease offering those services. ESMA also reminded market participants that entities established outside the EU are not permitted, outside the narrow reverse solicitation exception, to provide MiCA services to EU clients, and that this applies in a business to business context as well.

For a bank, that removes the discretion. Onboarding or continuing to serve an unauthorised crypto-asset service provider is no longer a risk appetite decision, because the counterparty is not lawfully operating. Authorisation status has moved from a favourable factor to a threshold condition.

The practical consequence

If you are seeking banking as a crypto-asset service provider, your MiCA authorisation status is now the first question, not a supporting document.

If you hold or transfer e-money tokens, a CASP authorisation alone may not be sufficient. Since 2 March 2026 those activities also require payment institution or electronic money institution authorisation, or a partnership with an authorised provider.

If you have already been refused or offboarded

Step 1. Establish the ground

Ask the institution to confirm whether the decision was taken on money laundering or terrorist financing risk or AML compliance grounds. Under EBA/GL/2023/04 the decision and its reason must be documented and available to the competent authority. Institutions frequently decline to explain, but the question changes the nature of the correspondence and creates a record.

Step 2. Use the complaint route

Where an institution communicates a refusal or termination it must advise you of the right to contact the relevant competent authority or alternative dispute resolution body, and provide the contact details. If that disclosure was not made, say so. This is the single most underused lever available to a rejected business.

Step 3. Diagnose which factor caused it

Map the file against the four risk factor categories. In most cases one of them carries the decision, and it is usually identifiable from what the institution asked for and what it did not accept before the file went quiet.

Step 4. Fix the structure, not the application

Reapplying with the same structure and better covering letters produces the same outcome. Where the cause is structural, the correction is structural: the entity chain, the licensing path, the safeguarding arrangement, or the described flows have to change.

Step 5. Re-approach with a complete file

Ownership and control fully documented to beneficial owner level, source of funds evidenced, licence status current, transaction monitoring described in terms of what it would detect rather than which vendor supplies it, and a flow description that matches the licence held.

Sequencing banking before you need it

The reason banking is the hardest part to fix is that it is the part most often addressed last. Structure gets decided first, usually on tax advice. Licensing gets decided second, usually on cost and timeline. Banking is approached once both are fixed, at which point the only remaining variables are the ones that cannot be changed without unwinding the previous two decisions.

Assessing banking feasibility first inverts that. It does not mean opening accounts before you need them, which is rarely possible. It means establishing, before you commit capital to a jurisdiction or a licence, which institutions will engage with the resulting structure and what they will require. Where the answer is that none will, that is a finding worth having before the application fee is paid rather than after.

Frequently asked questions

Why do banks reject crypto businesses?

Banks reject crypto businesses through de-risking, which the European Banking Authority defines as refusing or terminating relationships with customers linked to higher money laundering or terrorist financing risk. The usual drivers are unclear ownership, licence status that does not match the activity described, and expected flows the institution cannot monitor.

Is there a legal right to a business bank account in the EU?

No. The right of access to a payment account with basic features under Directive 2014/92/EU applies to consumers, not to companies. A business has no equivalent entitlement, so the route to an account is making the application approvable rather than asserting a right that does not exist.

What must a bank do before refusing a business relationship?

Under EBA Guidelines EBA/GL/2023/04, an institution should satisfy itself that it has considered and rejected all mitigating measures that could reasonably apply before rejecting or terminating a relationship. It must document the decision and its reason and make that documentation available to its competent authority on request.

Can a bank refuse an entire category of customers?

The EBA has stated that de-risking entire categories of customers without due consideration of individual risk profiles may be unwarranted and a sign of ineffective risk management. Guidelines EBA/GL/2023/04 require policies that do not result in blanket refusal of categories assessed as presenting higher risk.

Does holding a MiCA licence guarantee banking access?

No. Authorisation removes the most common blocking objection but obliges no institution to onboard. Since 1 July 2026 an unauthorised crypto-asset service provider serving EU clients is in breach of EU law, so the absence of a licence now operates as close to a decisive objection.

Why did our account get closed after we onboarded successfully?

Ongoing monitoring compares actual activity against what was declared at onboarding. Where volumes, counterparties, jurisdictions or product mix diverge from the file, the relationship is reassessed. Divergence between the declared model and the observed flow is a frequent cause of later termination.

Should we apply for banking before or after licensing?

Assess banking feasibility before committing to a licensing path, because the licence you pursue determines which institutions will engage with you. Formal applications are usually made once the corporate structure is settled and the licence application is filed or granted, depending on the institution's own policy.

What risk factors do banks weigh for crypto clients?

EBA Guidelines EBA/GL/2021/02, extended to crypto-asset service providers from 30 December 2024, group them as customer, product and transaction, delivery channel, and geographic risk factors. For crypto they specifically note innovative technologies, instant cross-border transfers and privacy-enhancing features.

Does an EMI account count as banking for a crypto business?

An electronic money institution account can carry operational flows but does not replace a credit institution relationship for safeguarding, settlement or treasury. Many structures use both. The right combination depends on the licence held and where client funds are required to be safeguarded.

Key resources

Source Reference What it covers
EBA Guidelines on ML/TF risk management and access to financial services EBA/GL/2023/04, 31 March 2023 Steps before refusing or terminating, documentation, complaint mechanisms
EBA Opinion on de-risking EBA/Op/2022/01, January 2022 Scale, drivers and impact of de-risking across the EU
EBA Guidelines on ML/TF risk factors EBA/GL/2021/02 The four risk factor categories applied to individual relationships
Amending Guidelines extending risk factors to CASPs EBA/GL/2023/03, applying from 30 December 2024 Crypto-specific risk factors and guidance for institutions banking CASPs
Payment Accounts Directive Directive 2014/92/EU Right of access to a basic payment account, consumers only
ESMA Statement on the End of Transitional Periods under MiCA ESMA75-113276571-1679, 17 April 2026 Position of unauthorised CASPs after 1 July 2026
EBA Opinion on supervisory priorities at the end of the NAL transition period EBA/OP/2026/01, 12 February 2026 PSD2 authorisation for CASPs transacting e-money tokens

Disclaimer

This article is for informational purposes only and does not constitute legal or regulatory advice. Regulatory requirements are subject to change. Consult a qualified advisor before making structural or compliance decisions.

DM Strategy advises fintech and crypto founders on structure, licensing, and banking as one interconnected decision. To discuss banking feasibility for your structure before you commit to a licensing path, book an introductory call at dmstrategy.io.

‍

Author:
Dionisijs Markovs

Interested in a conversation?