Why Crypto and Payment Businesses Get Rejected by Banks
At a glance
1. Most refusals are de-risking, which the European Banking Authority defines as refusing or terminating a relationship with a customer or category of customers associated with higher money laundering or terrorist financing risk.
2. EBA Guidelines EBA/GL/2023/04 require an institution to consider and reject all reasonable mitigating measures before refusing or terminating, and to document the decision and its reason.
3. The EBA has stated that de-risking whole categories of customers without considering individual risk profiles may be unwarranted and a sign of ineffective risk management.
4. Since 30 December 2024, amended Guidelines EBA/GL/2023/03 give institutions specific guidance on the risks to weigh when dealing with crypto-asset service providers, which is why licence status now drives banking outcomes.
5. There is no right to a business bank account in EU law. The right of access to a payment account with basic features under Directive 2014/92/EU applies to consumers, not to companies.
A bank account is usually the first thing a fintech or crypto business discovers it cannot get, and the last thing anyone told it to plan for. The application is declined without a reason, or the account is opened and closed six months later. The founder reads it as a commercial decision, or as prejudice against the sector, and applies to the next institution with the same file.
In most cases the cause is neither commercial nor prejudicial. It is structural, it was created months earlier, and it is visible in the application documents. This article sets out what the rules actually require of an institution before it refuses you, which risk factors decide the outcome, why a correctly incorporated company still gets declined, and what to do if you have already been refused.
What de-risking is, and why it sits behind most refusals
De-risking is a decision by a credit or financial institution to refuse to enter into, or to terminate, a business relationship with an individual customer or a category of customers associated with higher money laundering or terrorist financing risk, or to refuse to carry out higher risk transactions. The European Banking Authority set out this definition in its January 2022 Opinion on de-risking and carried it into Guidelines EBA/GL/2023/04.
Institutions de-risk for three reasons the EBA has identified. The money laundering, terrorist financing or reputational risk exceeds their appetite. They lack the knowledge or expertise to assess the risk attached to a specific business model. Or the expected cost of compliance outweighs the anticipated profit from the relationship.
Only the first of those is about you. The second and third are about the institution, and they explain why the same file can be declined by one bank and accepted by another without anything changing on your side. An institution with no crypto-competent analyst will not build one for a single applicant. This is why shopping the same application around rarely works, and why the institution's own capability matters as much as your risk profile.
What an institution must do before it refuses you
EBA Guidelines EBA/GL/2023/04, published 31 March 2023, set out the policies, procedures and controls institutions should have in place when providing access to financial services, and the steps they should take when considering whether to refuse or terminate a relationship on money laundering, terrorist financing or AML compliance grounds. They complement the separate Guidelines on ML/TF risk factors.
The guidelines are addressed to institutions, not to customers, but they are public, and they describe a process that produces a documented decision. Knowing what that process requires tells you what to ask for.
What no institution owes you
It is worth being precise here, because a great deal of published commentary is not. EU law does create a right of access to a payment account with basic features. That right sits in Directive 2014/92/EU, the Payment Accounts Directive, and it applies to consumers. It does not extend to companies.
A business therefore has no entitlement to an account. What it has is a set of procedural expectations on the institution: that the decision be individual rather than categorical, that mitigations be considered, that the reason be documented, and that a complaint route be disclosed. Those are real and worth using. They are not a right to be onboarded.
The practical consequence is that the route to banking is not asserting a right. It is making the file approvable, which means removing the specific risk factors that cause an analyst to decline rather than escalate.
The risk factors that decide the outcome
EBA Guidelines EBA/GL/2021/02 set out the money laundering and terrorist financing risk factors institutions should consider when assessing individual business relationships. Amending Guidelines EBA/GL/2023/03 extended them to crypto-asset service providers and added guidance for other credit and financial institutions on the risks to consider when entering business relationships with CASPs or otherwise becoming exposed to crypto-assets. They apply from 30 December 2024.
The guidelines group risk factors into four categories. An application is assessed against all four at once, and a serious problem in any one of them can decide the outcome on its own.
For crypto-asset service providers specifically, the amended guidelines note that risk can be increased by the use of innovative technologies, by instant transfers of crypto-assets across the world, and by services that contain privacy-enhancing features. An institution reading your application is looking for whether you have recognised those and built controls against them, not for whether they are present.
Why a correctly incorporated company still gets declined
Three things have to agree: the corporate structure, the licence or registration held, and the expected flow of funds. Most refusals are a disagreement between two of them.
The commonest pattern is a structure built for tax or for investor optics that does not support the licensing path, presented to an institution that reads the mismatch as either a control weakness or an attempt at opacity. A holding company in one jurisdiction, an operating company in another, a licence applied for in a third, and customer flows arriving from a fourth is a defensible arrangement. It is also four separate explanations an analyst has to accept, and each one is a point at which the file can be declined instead of escalated.
The second pattern is a licence that does not cover the activity described. A registration permitting exchange services does not support an application describing custody, payouts to third parties and stored client balances. The institution is not obliged to reconcile the two, and generally will not.
The third is a flow description that cannot be monitored. Where an institution cannot see how it would detect an anomaly in your expected activity, it cannot hold the relationship within its own supervisory obligations, and the mitigation step in EBA/GL/2023/04 has no available answer.
What changed with MiCA, and why licence status now decides banking
Before MiCA, an institution weighing a crypto client was making a judgement about an unregulated or nationally registered counterparty. That judgement has now largely been made for it.
The MiCA transitional period closed across the EU on 1 July 2026. In its statement of 17 April 2026, ESMA confirmed that after that date any entity providing crypto-asset services to EU clients without a MiCA licence is in breach of EU law and must cease offering those services. ESMA also reminded market participants that entities established outside the EU are not permitted, outside the narrow reverse solicitation exception, to provide MiCA services to EU clients, and that this applies in a business to business context as well.
For a bank, that removes the discretion. Onboarding or continuing to serve an unauthorised crypto-asset service provider is no longer a risk appetite decision, because the counterparty is not lawfully operating. Authorisation status has moved from a favourable factor to a threshold condition.
If you have already been refused or offboarded
Step 1. Establish the ground
Ask the institution to confirm whether the decision was taken on money laundering or terrorist financing risk or AML compliance grounds. Under EBA/GL/2023/04 the decision and its reason must be documented and available to the competent authority. Institutions frequently decline to explain, but the question changes the nature of the correspondence and creates a record.
Step 2. Use the complaint route
Where an institution communicates a refusal or termination it must advise you of the right to contact the relevant competent authority or alternative dispute resolution body, and provide the contact details. If that disclosure was not made, say so. This is the single most underused lever available to a rejected business.
Step 3. Diagnose which factor caused it
Map the file against the four risk factor categories. In most cases one of them carries the decision, and it is usually identifiable from what the institution asked for and what it did not accept before the file went quiet.
Step 4. Fix the structure, not the application
Reapplying with the same structure and better covering letters produces the same outcome. Where the cause is structural, the correction is structural: the entity chain, the licensing path, the safeguarding arrangement, or the described flows have to change.
Step 5. Re-approach with a complete file
Ownership and control fully documented to beneficial owner level, source of funds evidenced, licence status current, transaction monitoring described in terms of what it would detect rather than which vendor supplies it, and a flow description that matches the licence held.
Sequencing banking before you need it
The reason banking is the hardest part to fix is that it is the part most often addressed last. Structure gets decided first, usually on tax advice. Licensing gets decided second, usually on cost and timeline. Banking is approached once both are fixed, at which point the only remaining variables are the ones that cannot be changed without unwinding the previous two decisions.
Assessing banking feasibility first inverts that. It does not mean opening accounts before you need them, which is rarely possible. It means establishing, before you commit capital to a jurisdiction or a licence, which institutions will engage with the resulting structure and what they will require. Where the answer is that none will, that is a finding worth having before the application fee is paid rather than after.
Frequently asked questions
Why do banks reject crypto businesses?
Banks reject crypto businesses through de-risking, which the European Banking Authority defines as refusing or terminating relationships with customers linked to higher money laundering or terrorist financing risk. The usual drivers are unclear ownership, licence status that does not match the activity described, and expected flows the institution cannot monitor.
Is there a legal right to a business bank account in the EU?
No. The right of access to a payment account with basic features under Directive 2014/92/EU applies to consumers, not to companies. A business has no equivalent entitlement, so the route to an account is making the application approvable rather than asserting a right that does not exist.
What must a bank do before refusing a business relationship?
Under EBA Guidelines EBA/GL/2023/04, an institution should satisfy itself that it has considered and rejected all mitigating measures that could reasonably apply before rejecting or terminating a relationship. It must document the decision and its reason and make that documentation available to its competent authority on request.
Can a bank refuse an entire category of customers?
The EBA has stated that de-risking entire categories of customers without due consideration of individual risk profiles may be unwarranted and a sign of ineffective risk management. Guidelines EBA/GL/2023/04 require policies that do not result in blanket refusal of categories assessed as presenting higher risk.
Does holding a MiCA licence guarantee banking access?
No. Authorisation removes the most common blocking objection but obliges no institution to onboard. Since 1 July 2026 an unauthorised crypto-asset service provider serving EU clients is in breach of EU law, so the absence of a licence now operates as close to a decisive objection.
Why did our account get closed after we onboarded successfully?
Ongoing monitoring compares actual activity against what was declared at onboarding. Where volumes, counterparties, jurisdictions or product mix diverge from the file, the relationship is reassessed. Divergence between the declared model and the observed flow is a frequent cause of later termination.
Should we apply for banking before or after licensing?
Assess banking feasibility before committing to a licensing path, because the licence you pursue determines which institutions will engage with you. Formal applications are usually made once the corporate structure is settled and the licence application is filed or granted, depending on the institution's own policy.
What risk factors do banks weigh for crypto clients?
EBA Guidelines EBA/GL/2021/02, extended to crypto-asset service providers from 30 December 2024, group them as customer, product and transaction, delivery channel, and geographic risk factors. For crypto they specifically note innovative technologies, instant cross-border transfers and privacy-enhancing features.
Does an EMI account count as banking for a crypto business?
An electronic money institution account can carry operational flows but does not replace a credit institution relationship for safeguarding, settlement or treasury. Many structures use both. The right combination depends on the licence held and where client funds are required to be safeguarded.
Key resources
Disclaimer
This article is for informational purposes only and does not constitute legal or regulatory advice. Regulatory requirements are subject to change. Consult a qualified advisor before making structural or compliance decisions.
DM Strategy advises fintech and crypto founders on structure, licensing, and banking as one interconnected decision. To discuss banking feasibility for your structure before you commit to a licensing path, book an introductory call at dmstrategy.io.

.jpg)