A Licence Opens the Market, Not a Bank Account
A licence is permission to do business, not an obligation on any bank to serve you. FinCEN MSB registration, a Hong Kong MSO licence, FINTRAC registration in Canada, a Lithuanian EMI, a Singapore MPI all confer the right to hold other people's money. None of them creates a duty on a bank to open an account. The gap between those two facts is the central operational risk of any fintech project: the licence is granted, the product is built, and there is nowhere to keep the funds.
The gap is structural, and regulators acknowledge it. In its stocktake of unintended consequences of 27 October 2021, the FATF defined de-risking as terminating or restricting relationships with whole categories of customers in order to avoid risk rather than manage it, and called the practice inconsistent with the risk-based approach. The main driver is not fear of the supervisor but arithmetic. The US Treasury's De-risking Strategy of April 2023 states plainly that the cost of due diligence and account monitoring often exceeds the revenue such accounts generate, and lists MSBs — more than 26,000 of them on FinCEN's register — among the hardest-hit segments.
The scale of the contraction has been measured once, and not recently. According to CPMI and SWIFT data published on 13 December 2021, the number of active correspondents fell roughly 25% between 2011 and 2020, and by 4% in 2020 alone, while the volume of cross-border payments rose 2% and their value 7%. The same flow now runs through fewer nodes, and every surviving node negotiates from strength. The CPMI correspondent banking dataset concluded with the 2022 figures: there is no official statistic for the segment as at 2026, so any "current percentage" in a provider's deck is an estimate, not a measurement.
Five Accounts, and Why They Cannot Sit in One Place
The correct mental model is not "the company's bank account" but a stack of accounts with different legal characters. Collapsing any two layers breaks either the licence or the customer's protection.
| Account type | What sits on it | Where it is held | Legal character |
|---|---|---|---|
| Operating | The firm's own money: capital, revenue, fees, payroll | Commercial bank | Ordinary deposit of the operator; forms part of its estate on insolvency |
| Safeguarding / client money | Customer funds received against e-money or for executing a payment | Credit institution, in a separate account explicitly marked as client funds | Segregated; outside the operator's estate if the regime is properly run. Not a customer deposit: no deposit guarantee applies |
| Settlement | Working liquidity for clearing in a specific payment system | Central bank (TARGET/TIPS, RTGS, the Fed) or the system itself | Central bank money; hard balance cap, no credit extended |
| Nostro at a correspondent | Currency liquidity where there is no direct access | Correspondent bank | The operator's deposit with a bank; concentrates both credit and de-risking risk |
| Pooled / collection via a provider | Customer flows routed through an EMI or BaaS partner | EMI, payment institution, sponsor bank | Nesting: the operator is a customer's customer. Chain transparency becomes your problem |
Separation is a licensing condition, not bookkeeping hygiene. As far back as 28 May 2020 the Bank of Lithuania issued guidelines to banks on opening accounts for EMIs and PIs, naming exactly three categories a bank should be able to provide — the institution's own current account, an account for segregating client funds, and an account for executing payments — and requiring objectivity and proportionality in decisions to refuse or close. The jurisdiction of the account is not neutral either: the booking centre determines the applicable law and the creditor queue, not just the currency and the time zone.
The key trap of 2026 is that a central bank settlement account does not replace safeguarding. The ECB decision of 27 January 2025 and the Eurosystem policy on non-bank PSP access expressly bar national central banks from offering safeguarding accounts to non-bank PSPs and crypto-asset service providers: the TARGET balance is limited to what settlement requires, with the ceiling set at twice the peak value of outgoing transfer orders over the preceding 12 months and a penalty for breaching it. Meanwhile PSD3 lists placement with a central bank as one safeguarding option — "where the central bank is willing". The Eurosystem has already said it is not.
Why Banks Say No: Nesting, Sanctions and Arithmetic
The first and dominant reason is nesting. The FFIEC BSA/AML manual describes a nested correspondent as a situation where a bank's customer makes its account available to third-party financial institutions the bank does not know, and treats it as elevated risk by definition. The Wolfsberg Group's guidance of 15 July 2026 frames the same thing in payments terms: nesting is where a PSP processes a payment for its customer's underlying customer. To a bank, a licensed operator with an agent network is not one customer but an unknown number of invisible end users.
The second layer is virtual IBANs. The EBA report on vIBANs of May 2024 maps six issuance models and pins the core problem: the master account holder does not know the end users, the supervisor cannot see the scale, and the IBAN country code may not match the country of the underlying account — leaving the jurisdiction for complaints unclear and deposit guarantee coverage ambiguous. What that means for real flows was shown by the joint work of the Estonian, Latvian and Lithuanian FIUs: in Q4 2023 financial-institution clients accounted for 24% of Lithuanian PI and EMI turnover and crypto-asset providers for a further 10%, while the number of Lithuanian EMIs had fallen to 76 and PIs to 43.
The third layer is sanctions. An operator with corridors into sensitive jurisdictions transfers sanctions risk to the correspondent, and the correspondent answers to its own regulator. Section 312 of the USA PATRIOT Act triggers enhanced due diligence automatically where the respondent operates under an offshore banking licence or from a jurisdiction flagged as problematic. Formally the bank need not diligence its customer's customers — but it must understand whether the activity fits the business model, which in practice amounts to the same thing.
Supervisors, for their part, do not endorse blanket refusals. The US interagency interpretive guidance SR 05-8 of 26 April 2005 still stands and says wholesale closure of MSB accounts is not required: risk gradation is. After its Opinion on de-risking of 5 January 2022, which named PIs and EMIs among the principal victims of blanket exit policies, the EBA issued Guidelines EBA/GL/2023/04 of 31 March 2023 on risk management and access to financial services. The HKMA's circular of 27 April 2023 told banks not to exclude entire industries from their target segments and specifically encouraged them to serve SFC-licensed virtual asset service providers. The net result: the regulator says "assess individually", the bank replies "assessed, not for us", and there is nothing substantive to appeal.
What the Bank Will Ask For: the Operator's Checklist
Until July 2026 the requirements had to be assembled anecdotally from practice. Now there is an industry benchmark: the Wolfsberg Group guidance on providing banking services to non-bank PSPs describes three archetypal business models (business remittance and FX, person-to-person remittance, merchant acquiring) and breaks enhanced due diligence into blocks. Below is what should be ready before the first conversation.
- The licence and its perimeter: proof of status, the list of permitted services, and evidence that actual activity fits inside it.
- Corporate and UBO structure, including every beneficial owner and each licensed entity in the group.
- The business model in numbers: corridors, currencies, customer types, share of non-residents, projected turnover and average ticket, product roadmap for 12–24 months.
- The full compliance stack: AML/CFT and sanctions policies, KYC and UBO verification, transaction monitoring (and whether it is genuinely real-time), screening tools and list sources, fraud controls down to IP and device tracking, SAR filing procedure.
- People: CVs and authority of the MLRO and compliance head, headcount, training programme and its frequency.
- Audit: internal and external financial-crime audit reports, findings and remediation plan, KYC backlog metrics.
- The partner network: agents, distributors, intermediaries — their due diligence, the split of AML responsibilities along the chain, and the oversight mechanism.
- Safeguarding: where client funds sit, how reconciliation is performed, who confirms balances.
- Wind-down plan and resolution pack — once asked for only by the regulator, now asked for by the bank.
Wolfsberg specifically notes that diligence is not a one-off: reviews are triggered by adverse media, ownership changes, licensing changes, financial-crime incidents and the appearance of new flows or intermediaries in the chain. The practical lesson: presenting yourself as "just a payments company" guarantees refusal. The opposite works — disclosing more than was asked for, before it is asked for.
Who Actually Provides the Service: a Regional Map for 2026
Universal banks have left the segment. Their place has been taken by specialised institutions for which serving operators is not a tolerated risk but the core product.
| Region | Who actually serves the segment | What to know |
|---|---|---|
| UK | New-generation clearing banks — ClearBank, LHV Bank (200+ clients including Wise and Airwallex), Griffin — and specialist EMIs: Clear Junction, BCB Group | A safeguarding account for an EMI is a separate product with its own price. CASS 15 has applied since 7 May 2026 |
| EU / EEA | Memo Bank, Banking Circle, Baltic and niche banks, EMI providers; and, for those who pass, a direct TARGET account. Memo Bank sells a ring-fenced (safeguarding) account for PIs and EMIs as an off-the-shelf product — a market rarity | Lithuania remains continental Europe's largest EMI hub but has been through a clean-up: 76 EMIs and 43 PIs remained by 2024 |
| Switzerland and Liechtenstein | Bank Frick, Sygnum and other FINMA-licensed banks | Historically the only combination of a banking licence with genuine appetite for financial intermediaries. Liechtenstein carries an EEA passport |
| United States | Sponsor banks behind BaaS chains — Cross River Bank, Column N.A., Lead Bank — plus a new wave of federal charters. Onboarding runs through a programme, not walk-in; programme client funds sit in an FBO (for benefit of) account at the sponsor bank, whose terms the bank sets, not the operator | After the 2023 collapse of Silvergate, Signature and SVB the gap was filled not by universal banks but by new charters: the OCC conditionally approved five national trust banks on 12 December 2025 |
| Canada | Specialist players: Peoples Group, DC Bank | Peoples Group is building a payments platform with Fiserv (25.02.2026) for the Real-Time Rail; DC Bank offers API banking, Interac e-Transfer and trust accounts; universal banks treat MSBs as an inherently high-risk segment |
| Hong Kong | Virtual banks (ZA Bank) and payment account providers; traditional banks under the HKMA circular | On 10 April 2026 the HKMA granted the first stablecoin issuer licences — to Anchorpoint Financial and HSBC |
| Singapore | Local banks for MPIs, plus regional neobanks | MAS is pushing onboarding speed through its circular on establishing sources of wealth, without lowering the diligence standard |
| Middle East | UAE banks operating under the CBUAE SVF, RPSCS and Payment Token Services regimes | The CBUAE rulebook requires a local licence; banking follows that licence, not a foreign one |
| Offshore | Banks without direct access to major-currency clearing | The bottleneck is the correspondent, not the account: section 312 triggers enhanced diligence on offshore licences automatically |
Hong Kong practice deserves a note in prose. The working MSO pattern is an operating account in EMI infrastructure of the Airwallex class first, a bank account later, backed by a trading history. A protection mechanism exists: after a wave of refusals the HKMA required retail banks to maintain a review mechanism for declined applications and a dedicated feedback channel (accountopening@hkma.gov.hk); lists of "friendly" banks in consultants' materials are unverifiable anecdote, not a guarantee.
A category of its own is renting someone else's licence. It solves the account question fastest and creates precisely the problem that makes banks refuse: you become one more layer of nesting. The wider logic of the segment in 2026 is mapped in the overview of banks by jurisdiction.
Direct Settlement Access Instead of a Correspondent
The main structural shift: a non-bank operator can increasingly do without a correspondent.
EU. Since October 2025 an EEA-authorised PI or EMI can open a settlement account in TARGET and TIPS. The Eurosystem policy announced on 19 July 2024 requires compliance with the same operational and technical requirements as credit institutions; there is no intraday credit, balances are capped, and the central bank will not open a safeguarding account.
United Kingdom. In its response to the discussion paper of 8 April 2025 the Bank of England tightened entry: an applicant must have been carrying on regulated activity for at least nine months, undergo a s166 assessment, and pass stage gates (mobilisation and live-proving). At the same time the Bank is exploring whether non-bank PSPs might hold client funds in an RTGS account — today they cannot even overnight. That is the single most consequential open decision for UK fintech.
United States. On 20 May 2026 the Federal Reserve put a payment account out for comment — a stripped-down account for clearing and settlement. Per analysis of the proposal, the balance is capped at 1 billion dollars, no interest accrues, there is no intraday credit and no discount window, and FedACH is excluded; comments closed on 27 July 2026, and decisions on Tier 3 applicants under the Guidelines of 15 August 2022 are temporarily paused. The legal backdrop remains hard: on 31 October 2025 the Tenth Circuit confirmed that a legally eligible institution has no right to a master account — the words "may receive" in 12 U.S.C. 342 leave the decision to the Reserve Bank's discretion. The regime is unpacked in the Fed payment accounts explainer.
Where Money in an EMI Account Actually Sits
Money in an EMI or payment institution account is not a bank deposit. Its protection rests on segregation and the discipline of the specific institution, and the record on that discipline is poor: in Policy Statement PS25/12 of 7 August 2025 the FCA reports that firms that became insolvent between Q1 2018 and Q2 2023 showed an average shortfall of 65% against the funds owed to clients. Over the same period the amount safeguarded by UK EMIs grew from roughly £11 billion in 2021 to £26 billion in 2024, with payment institutions holding around £6 billion.
The regulatory answer is CASS 15. Since 7 May 2026 an interim regime applies: internal and external reconciliations at least once on every reconciliation day, same-cycle remediation of any shortfall (including from the firm's own funds), a monthly return to the FCA, an annual safeguarding audit for everyone except firms safeguarding under £100,000 across 53 weeks, and a resolution pack. The end-state regime with a statutory trust has been deferred pending further consultation — the detail sits in the UK regime explainer.
Three questions worth putting to whoever holds your money. Which bank and which country hosts the safeguarding account — that determines the applicable law on insolvency. One bank or several — concentration means a single account closure stops the whole business. Does your payment pass through intermediate providers — if so, you sit at the end of a nesting chain, and in a stress scenario your funds will take the longest to untangle.
Banking Strategy and What to Do When Refused
Rule one: banking is designed before the licence application, not after the licence is granted. In many jurisdictions the regulator wants to see a client-funds account at the authorisation stage, while the bank wants to see the licence — escaping that loop takes months and is solved by pre-agreement with a provider before filing.
Rule two: at least two safeguarding providers in different groups. This has stopped being best practice: under the PSD3 compromise text concentrating client funds in a single bank is prohibited.
Rule three: a right to reasons and to notice now exists, but narrowly. In the UK the Payment Services and Payment Accounts (Contract Termination) (Amendment) Regulations 2025 come into force on 28 April 2026: for contracts entered into from that date, termination requires at least 90 days' notice and an explanation sufficiently detailed and specific for the user to understand the reason; earlier contracts keep a two-month notice period. The carve-outs are broad — money laundering suspicion, Immigration Act requirements, reasonable suspicion of a connection to serious crime, a direction from a regulator — and in those cases termination can be immediate and unexplained. The reform is real for an operator being exited on risk appetite, and worth nothing to one being exited on AML grounds.
In the US the pendulum has swung harder. Executive Order 14331, "Guaranteeing Fair Banking for All Americans", of 7 August 2025 gave the banking agencies 180 days to strip reputation risk out of their guidance, 120 days to review supervised institutions for politicised or unlawful debanking up to fines and consent decrees, and directed Treasury to produce a counter-debanking strategy. The Federal Reserve dropped reputational risk from its examination programmes on 23 June 2025, and on 7 April 2026 the OCC and FDIC issued a final rule expressly barring the agencies from criticising banks or pressing them to close accounts by reference to reputation risk, political or religious views, or lawful business activity. The caveat matters: the rule binds the regulator, not the bank. The commercial decision to refuse still belongs to the bank.
The price of concentrating on a single gateway was shown by the OCC consent order against Community Federal Savings Bank of 24 April 2026: in consulting circles CFSB had for years figured as the default gateway for non-resident MSBs, and under remediation it is hardening KYC reviews, slowing payments and offboarding the riskier tail. Plan B for dependent programmes: build the second banking leg before the closure letter, agree any volume migration with the receiving bank in advance — an abrupt flow shift is itself an alert — and re-check your own reporting, because the bank's lookback will resurface old transactions and the questions will land on its clients.
What to do when refused. Ask for written reasons — in the UK from April 2026 that is a right; elsewhere it is an argument to make in correspondence. Check which ground is cited: risk appetite is contestable, and is usually contested by switching provider, whereas an AML ground effectively is not. Do not pull funds in a panic: abruptly emptying an account is itself a SAR trigger. In parallel, close the dependency — direct payment system access, where available, removes the correspondent question entirely. And above all, do not build a business plan on a single banking relationship: before 2026 that was a design error; after the settlement-access reforms it is simply a refusal to fix one.
Q/A
Why the bank refused despite a licence and a clean compliance record
Because the decision is commercial, not regulatory. The US Treasury's 2023 De-risking Strategy names economics as the principal driver: the cost of diligence and monitoring on such an account frequently exceeds the revenue it produces. Add nesting — the bank sees not you but an unknown number of your agents and their customers — and you get a refusal with no stated rationale. The route around it is not appeal but choosing a provider for whom operators are the core product, and disclosing the chain before being asked.
Whether client funds can be held in a central bank account
In the euro area, no. The ECB decision of 27 January 2025 and the Eurosystem policy expressly bar central banks from offering safeguarding accounts to non-bank PSPs and crypto-asset providers: a TARGET or TIPS account is a settlement account, its balance is limited to settlement needs, and the ceiling is set at twice the peak of outgoing transfer orders over 12 months. PSD3's reference to a central bank as a safeguarding option remains conditional on the willingness of the particular central bank, and the Eurosystem has stated its position. The Bank of England is exploring the reverse for RTGS, but as at August 2026 there is no decision.
What the 2025–2026 debanking reforms actually change
In the UK, from 28 April 2026: at least 90 days' notice and a duty to give a sufficiently detailed and specific explanation, for contracts entered into from that date. But the carve-outs cover money laundering suspicion, serious crime and regulatory direction — which is most real-world fintech account closures. In the US, Executive Order 14331 and the OCC/FDIC final rule of 7 April 2026 removed reputation risk from the supervisory toolkit: that binds the regulator, but does not oblige any bank to open or keep an account.
How VASPs and CASPs are banked after MiCA and the GENIUS Act
A licence improved the negotiating position without settling the question: AMLR (Regulation (EU) 2024/1624), applying from 10 July 2027, introduces in Article 37 a dedicated enhanced due diligence regime for cross-border correspondent relationships between crypto-asset service providers and third-country respondents. In the EU a payments layer was added: on the EBA's position the transition period for CASP activity involving e-money tokens ended on 2 March 2026, and such activity requires PSP status. In the US the vector runs the other way: the GENIUS Act pulls stablecoin issuers under federal rules — the OCC proposed its requirements in March 2026 — and the five national trust charters of December 2025 mean the largest crypto players are ceasing to be bank customers and becoming banks themselves.