A financial licence permits an activity; it obliges no bank to open or keep the operator's account. For an MSB, an MSO, an EMI or a payment institution, the banking set-up is as load-bearing as capital and the AML programme: without an operating account there is no payroll, without a safeguarding account there is no right to take client money, and without a correspondent there are no currency corridors. The bank, meanwhile, pays more to serve such a customer than an ordinary company and answers to its own regulator for the customer's flows — hence the refusals, the long questionnaires and the constant requests for information.
Concept
The statuses loosely called "a licence to handle money" differ in law. Some are AML registrations, some are permissions to carry on an activity, and some additionally require client funds to be safeguarded. That determines which account is needed and what the bank will test.
| Status | What it confers | What happens to client funds |
|---|---|---|
| US: FinCEN MSB registration and state money transmitter licences | Registration is a federal AML obligation; the right to conduct money transmission comes from state licences. The 2005 interagency guidance tells banks to confirm the two separately | Held in the operator's bank accounts; in a BaaS chain, in an FBO (for benefit of) account at the sponsor bank |
| Canada: FINTRAC MSB registration and the RPAA | FINTRAC registration is required before remitting, exchanging or dealing in virtual currency begins. Separately, payment service providers register with the Bank of Canada under the Retail Payment Activities Act | Since 8 September 2025 the RPAA has required end-user funds to be safeguarded |
| Hong Kong: Customs MSO licence | A licence under the AMLO (Cap. 615) for remittance and money changing; the regime has applied since 1 April 2012 | The status concerns AML supervision of remittance; where money sits in transit is set by the contract with a bank or payment provider |
| EU: EMI and payment institution | Authorisation under EMD2 and PSD2, with an EEA passport | Mandatory safeguarding: a separate account at a credit institution, secure liquid assets, or insurance/guarantee |
| UK: EMI and authorised payment institution | FCA authorisation | Safeguarding under reg. 23 of the PSRs 2017 and the EMRs, plus CASS 15 since 7 May 2026 |
| Singapore: MPI | A MAS licence under the Payment Services Act 2019 | The bank tests the licence, its perimeter and compliance with MAS requirements |
The common denominator is simple: neither a registration nor a licence places any duty on a bank to open an account. The result is a loop familiar to every payments start-up: at authorisation the regulator wants to see a client-funds account, while the bank wants to see a licence already granted. The banking set-up is therefore designed before the application, and the provider is lined up in advance with a pre-agreement.
Why a Licensed Operator Is Expensive for a Bank
The Economics of Refusal
In its stocktake of unintended consequences of 27 October 2021, the FATF defined de-risking as terminating or restricting relationships with whole categories of customers to avoid risk instead of managing it, and called the practice inconsistent with the risk-based approach. The main driver is arithmetic. The US Treasury's De-risking Strategy of April 2023 states that the cost of due diligence and monitoring on such accounts often exceeds the revenue they generate, and lists MSBs among the hardest-hit segments; FinCEN's register holds more than 26,000 of them.
The contraction has been measured, but not recently. According to CPMI and SWIFT data published on 13 December 2021, the number of active correspondents fell roughly 25% between 2011 and 2020, and by 4% in 2020 alone, while the volume of cross-border payments rose 2% and their value 7%. The same flow now runs through fewer nodes, and each surviving node sets the terms. The CPMI correspondent banking dataset ended with the 2022 figures, so there is no official statistic for the segment as at 2026; any "current percentage" in a provider's deck remains an estimate. The mechanics of correspondent relationships are covered in the article on correspondent banking and safeguarding.
Nested Risk
The dominant factor is nested access to banking infrastructure. The FFIEC BSA/AML manual describes nested relationships as the use of a bank's correspondent account by one or more financial institutions through their relationship with the bank's direct customer, and treats them as a higher-risk factor. The Wolfsberg Group's 2026 guidance on serving non-bank PSPs frames the same thing in payments terms: a PSP processes a payment for its customer's underlying customer. To a bank, a licensed operator with an agent network means an unknown number of invisible end users behind a single customer.
The diagram below shows nesting from the bank's side: the operator, its agents and other PSPs stand between the bank and the end payer, while the bank alone answers to the regulator.
Virtual IBANs
A separate factor is virtual IBANs. The EBA report on vIBANs of May 2024 maps six issuance models and pins the core problem: the master account holder does not know the end users, the supervisor cannot see the scale, and the IBAN country code may not match the country of the underlying account — leaving the jurisdiction for complaints and deposit guarantee coverage unclear. The joint work of the Estonian, Latvian and Lithuanian FIUs showed what this means for real flows: in Q4 2023 financial-institution clients accounted for 24% of Lithuanian PI and EMI turnover and crypto-asset providers for a further 10%.
Sanctions and Country Risk
An operator with corridors into sensitive jurisdictions transfers sanctions risk to the correspondent, which answers to its own regulator. Section 312 of the USA PATRIOT Act triggers enhanced due diligence automatically where the respondent is a foreign bank operating under an offshore banking licence or under a licence from a jurisdiction designated as non-cooperative on AML or subject to special measures under section 311. Formally the bank need not diligence its customer's customers, but it must understand whether the activity fits the declared model, which in practice comes to much the same thing.
What Regulators Expect: De-risking by Jurisdiction
Supervisors in every major centre publicly oppose blanket refusals while leaving the bank free to decide each customer on its merits. The difference lies in how much procedure is imposed on a refusal.
United States
Interagency interpretive guidance SR 05-8 of 26 April 2005, issued by the Federal Reserve, FDIC, OCC, OTS, NCUA and FinCEN, still sets the baseline for MSB due diligence: apply the CIP, confirm FinCEN registration, confirm state licensing, establish agent status and conduct a basic BSA/AML risk assessment. For higher-risk customers a bank may ask for the AML programme, independent testing results, a list of agents and their locations and agent-management procedures, and may carry out an on-site visit. The key line in the guidance text: banks are not expected to act as the de facto regulators of the MSB industry. The same text says the BSA does not require an account to be closed merely because a SAR has been filed on it.
The joint statement of five agencies of 6 July 2022 restated the logic more broadly: no customer type presents a single uniform level of risk, and banks that comply with the BSA and manage risk are neither prohibited nor discouraged from serving customers of any class; nonbank financial institutions are named among those categories. The statement creates no new requirements, and the decision on any given account stays with the bank.
United Kingdom
UK law goes beyond declarations. Regulation 105 of the Payment Services Regulations 2017 requires a credit institution to give payment institutions, EMIs and even applicants for authorisation access to payment account services on an objective, non-discriminatory and proportionate basis, extensive enough for them to operate unhindered. A bank that refuses or withdraws access must give duly motivated reasons in a notification to the FCA. The rule creates no right to a particular account, but it leaves a trace with the regulator: the refusal acquires written reasons that the FCA sees. Since 28 April 2026 a longer termination notice period has been added (see below).
European Union
The counterpart of regulation 105 is Article 36 PSD2: payment institutions' access to credit institutions' account services on an objective, non-discriminatory and proportionate basis, with duly motivated reasons for any rejection given to the competent authority. The EBA Opinion on de-risking of 5 January 2022 showed how it works in practice: the provision is applied divergently, rejections reported by PIs and EMIs were not reflected in notifications to national authorities, banks' decisions were often final with no review, and some institutions ended up holding large amounts of cash on their own premises. The EBA advised the Commission to clarify Article 36 in the PSD2 review, introduce a notification template and extend the duty to the offboarding of existing relationships.
Guidelines EBA/GL/2023/04 of 31 March 2023 followed: before refusing, consider lighter measures (the intensity of monitoring, targeted product restrictions), document the decision and its reason for the supervisor, and tell the customer how to complain. One detail matters: for payment institutions the EBA considered a distinct approach through the PSD2 revision necessary, so the guidelines set a general access standard while the PI and EMI question was left to the new payments directive. As early as 28 May 2020 the Bank of Lithuania issued guidelines to banks on EMI and PI accounts, naming three categories a bank should be able to provide — the institution's own current account, an account for segregating client funds and an account for executing payments — and requiring objectivity and proportionality in decisions to refuse or close.
Hong Kong and Singapore
The HKMA's circular of 27 April 2023 told banks not to exclude entire industries from their target segments and specifically encouraged them to serve SFC-licensed virtual asset service providers. Back in 2018 the regulator required retail banks to maintain a review mechanism for declined applications and a dedicated feedback channel (accountopening@hkma.gov.hk). MAS is pushing onboarding speed through its circular on establishing sources of wealth without lowering the diligence standard.
The outcome is the same everywhere: the regulator says "assess individually", the bank replies "assessed, not for us", and there is nothing substantive to challenge. Procedural rights (regulation 105, Article 36, notice periods) make a refusal visible and documented without changing its result.
The Licensed Operator's Account Architecture
An operator usually needs several accounts of different legal character. Mixing funds on any one of them creates both a licensing risk and a risk to clients.
| Account type | What sits on it | Where it is held | Legal character |
|---|---|---|---|
| Operating | The firm's own money: capital, revenue, fees, payroll | Commercial bank | Ordinary deposit of the operator; forms part of its estate on insolvency |
| Safeguarding / client money | Customer funds received against e-money or for executing a payment | Credit institution, in a separate account marked as client funds | Segregated; outside the operator's estate if the regime is properly run. Not a customer deposit: no deposit guarantee applies |
| Settlement | Working liquidity for clearing in a specific payment system | Central bank (TARGET/TIPS, RTGS, the Fed) or the system itself | Central bank money; hard balance cap, no credit extended |
| Nostro at a correspondent | Currency liquidity where there is no direct access | Correspondent bank | The operator's deposit with a bank; concentrates credit risk and de-risking risk |
| Pooled / collection via a provider | Customer flows routed through an EMI or BaaS partner | EMI, payment institution, sponsor bank | Nesting: the operator is a customer's customer, and chain transparency becomes its obligation |
The jurisdiction of the account is not neutral either: the booking centre determines the applicable law and the creditor queue, as well as the currency and the time zone.
Safeguarding Accounts by Jurisdiction
United Kingdom. Regulation 23 of the PSRs 2017 requires client funds to be kept segregated and, if still held at the end of the business day following receipt, placed in a separate account with a credit institution or the Bank of England, or invested in FCA-approved secure liquid assets held with a custodian; the alternative is insurance or a guarantee. CASS 15, in force since 7 May 2026, adds account-level discipline: the word "safeguarding" should be included in account names wherever possible (15.2.2G); for each account the institution signs an acknowledgement letter in the Annex 1 template and asks the bank to countersign it (15.7.3R and 15.7.5R); when choosing a bank it considers the bank's capital, creditworthiness and the size of its funds relative to that capital (15.6.4G); and it considers spreading funds across several banks (15.6.6G).
In practice a UK bank opening a safeguarding account signs a document acknowledging that the funds on it are held for the operator's clients, and such an account is usually sold as a separate product at a separate price.
EU. Article 10 PSD2 (applied to EMIs through EMD2) follows a similar structure, but without a central bank option: users' funds are never commingled with the funds of any other person; if they have not been delivered to the payee or transferred to another PSP by the end of the business day following receipt, they are placed in a separate account at a credit institution or invested in secure, liquid, low-risk assets defined by the competent authority, and are insulated under national law from the claims of other creditors, in particular on insolvency. The alternative is an insurance policy or comparable guarantee from an insurer or credit institution outside the institution's own group. The PSD3 compromise text expressly calls concentration a significant risk, particularly where all funds sit with a single credit institution, and instructs the EBA to develop technical standards on when concentration should be avoided.
United States. There is no federal safeguarding regime for MSBs; in a BaaS model programme client funds sit in an FBO account at the sponsor bank, and the bank sets the account's terms. The joint statement of the Federal Reserve, FDIC and OCC of 25 July 2024 on third-party deposit arrangements lists the risks of exactly this structure: the bank may lack access to the end-user system of record, operations are fragmented across several third parties, rapid growth outpaces controls, and end users mistake a non-bank intermediary for an insured bank.
Canada. Since 8 September 2025 the RPAA has required end-user funds to be safeguarded, and a bank opening an account for a Canadian PSP will ask how that regime is being met.
Crypto firms. For VASPs and CASPs the bank account serves as the fiat rail: client money in and out. The bank looks at the same things as for a payments operator, plus compliance with the travel rule and the chain of crypto counterparties. In the UK a dedicated regulation 34A on enhanced due diligence applies from 1 February 2027 to cryptoasset exchanges and custodians with third-country respondents; the UK client-asset regime for crypto firms is covered in the article on UK safeguarding and the crypto regime.
A Central Bank Account Does Not Replace Safeguarding
A central bank settlement account is not a safeguarding account. The ECB decision of 27 January 2025 and the Eurosystem policy on non-bank PSP access expressly bar national central banks from offering safeguarding accounts to non-bank PSPs and crypto-asset service providers: the TARGET balance is limited to what settlement requires, capped at twice the peak of outgoing transfer orders over the preceding 12 months, with a penalty for breaching it. Meanwhile PSD3 lists placement with a central bank as one safeguarding option — "where the central bank is willing". The Eurosystem has already said it is not.
What the Bank Asks the Operator For
The starting point is a questionnaire. For respondent banks the standard is the Wolfsberg CBDDQ; for other financial institutions it is the shorter FCCQ; their structure, sections and common completion errors are covered in the article on Wolfsberg questionnaires. The Wolfsberg Group's 2026 guidance on serving non-bank PSPs — MSBs, third-party payment processors, fintechs and EMIs, excluding pure VASPs and CASPs — describes three archetypal models (business remittance and FX, person-to-person remittance, merchant acquiring) and encourages banks to supplement generic questionnaires with tailored ones on the business model, funds flows, corridors and controls. Below is the pack a licensed operator prepares before the first conversation.
| Block | What is disclosed |
|---|---|
| The licence and its perimeter | Proof of status, the list of permitted services, and evidence that actual activity fits inside it |
| Corporate and UBO structure | Every beneficial owner and each licensed entity in the group |
| Business model and flow of funds | Corridors, currencies, customer types and segments, share of non-residents, projected turnover and average ticket, a map of money moving from payer to payee showing every account, product roadmap for 12–24 months |
| Correspondents and nested strategy | The banks and payment partners the money passes through; whether the operator serves other PSPs and on what terms; how AML and sanctions responsibility is split along the chain |
| The full compliance stack | AML/CFT policies, an EWRA from the last 12 months, KYC and UBO verification, transaction monitoring (real-time or not), fraud controls down to IP and device tracking, SAR filing procedure, backlogs in monitoring and KYC refresh |
| Sanctions and payment transparency | Screening tools and lists, real-time and free-text-field screening, compliance with FATF R.16 and the travel rule |
| People | CVs and authority of the MLRO and compliance head, headcount relative to the growth strategy, training programme and its frequency |
| Independent assurance | Internal and external financial-crime audit reports, the reputation of the audit firm, findings and remediation plan; the bank may run its own sample testing of customer files and transactions |
| The partner network | Agents, distributors, intermediaries: their due diligence and the oversight mechanism |
| Safeguarding and virtual accounts | Where client funds sit, how reconciliation is performed, who confirms balances, whether vIBANs are used |
| Wind-down plan and resolution pack | Once asked for only by the regulator, now asked for by the bank as well |
Wolfsberg specifically notes that diligence is not a one-off: reviews are triggered by material adverse media, ownership changes, licensing changes, financial-crime incidents and the appearance of new flows or intermediaries in the chain. Where risk cannot be sufficiently mitigated, particularly given reduced end-to-end visibility, the bank is expected to choose a risk-control strategy, up to and including declining. The practical lesson: describing oneself as "just a payments company" all but guarantees refusal. What works is surplus transparency, offered before the question is asked.
Types of Banking Partner
Universal banks have largely left the segment. Their place has been taken by institutions for which serving operators is the core product, and by chains in which a licensed operator reaches a bank through an intermediary.
| Partner type | What it offers | Main risk |
|---|---|---|
| Large universal bank | Stability, a broad correspondent network, cheap liquidity | Narrow risk appetite, slow onboarding, closure when group policy shifts |
| Specialist fintech bank | Safeguarding accounts as a product, APIs, agency vIBANs, understanding of the model | Concentration: the bank has many similar customers, and supervisory pressure on it hits them all at once |
| Sponsor bank / BaaS | Access to settlement and accounts through a programme, an FBO account for client funds | Dependence on the middleware intermediary and on the bank's own supervisory standing |
| An EMI as the operator's bank | A fast start: an agency arrangement or a pooled account with sub-accounts | Nesting: the operator becomes a customer's customer and its funds part of someone else's safeguarding pool |
Chains break in public. On 14 June 2024 the Federal Reserve took action against Evolve Bancorp and Evolve Bank & Trust for unsafe practices in partnerships with fintech companies: there was no effective framework for managing the risks of those partnerships, and AML controls and consumer compliance were inadequate; the regulator noted separately that the action was distinct from the bankruptcy of Synapse Financial Technologies. The OCC consent order against Community Federal Savings Bank of 24 April 2026 concerns bank-wide BSA/AML deficiencies that the order says were largely unrelated to digital-asset customers: controls had not kept pace with growth in payment processing, including suspicious-activity monitoring, customer due diligence, independent testing and staffing; the OCC required a remediation plan and an independent SAR look-back. The order does not establish that CFSB delayed payments or offboarded any particular client, but for programmes that depend on such a bank it is a signal to build a second route in advance.
The UK has tightened the rules for pooled arrangements: since 30 June 2026 a regulated person opening a pooled account for a customer must understand its purpose and intended use, check this against what it knows of the customer, assess the risk and consider controls. An EMI serving another licensee through a shared account now documents that reasoning just as a bank would.
A Regional Map for 2026
| Region | Who actually serves the segment | What to know |
|---|---|---|
| UK | New-generation clearing banks — ClearBank, LHV Bank (200+ clients including Wise and Airwallex), Griffin — and specialist EMIs: Clear Junction, BCB Group | A safeguarding account for an EMI is a separate product with a CASS 15 acknowledgement letter |
| EU / EEA | Memo Bank, Banking Circle, Baltic and niche banks, EMI providers; and, for those who pass, a direct TARGET account. Memo Bank sells a ring-fenced (safeguarding) account for PIs and EMIs as an off-the-shelf product, a market rarity | Lithuania remains continental Europe's largest EMI hub but has been through a clean-up: the Bank of Lithuania counted 76 EMIs and 43 PIs at the end of 2024 |
| Switzerland and Liechtenstein | Bank Frick (Liechtenstein, FMA-supervised), Sygnum and other FINMA- and FMA-licensed banks | Historically a rare combination of a banking licence with appetite for financial intermediaries. Liechtenstein carries an EEA passport |
| United States | Sponsor banks behind BaaS chains — Cross River Bank, Column N.A., Lead Bank — plus a new wave of federal charters. Onboarding runs through a programme, with no walk-in | The OCC conditionally approved five national trust bank charters on 12 December 2025. Its active trust-bank list as at 31 July 2026 includes BitGo, Fidelity Digital Assets, First National Digital Currency Bank and Paxos; Ripple is absent |
| Canada | Specialist players: Peoples Group, DC Bank | Peoples Group is building a payments platform with Fiserv (25.02.2026) for the Real-Time Rail; DC Bank offers API banking, Interac e-Transfer and trust accounts; universal banks treat MSBs as a high-risk segment |
| Hong Kong | Virtual banks (ZA Bank) and payment account providers; traditional banks under the HKMA circular | On 10 April 2026 the HKMA granted the first stablecoin issuer licences under the Stablecoins Ordinance, in force since 1 August 2025, to Anchorpoint Financial Limited and The Hongkong and Shanghai Banking Corporation Limited; as at September 2026 the HKMA register still lists only those two licensees. By 22 August, Anchorpoint's HKDAP was live only in beta for corporates and professional investors, while HSBC still described its HKD stablecoin launch as planned for the second half of 2026 |
| Singapore | Local banks for MPIs and regional payment providers | Emphasis on onboarding speed with an unchanged source-of-wealth standard |
| Middle East | UAE banks operating under the CBUAE SVF, RPSCS and Payment Token Services regimes | The CBUAE rulebook requires a local licence; banking follows that licence, and a foreign one does not substitute for it |
| Offshore | Banks without direct access to major-currency clearing | The bottleneck is the correspondent: section 312 triggers enhanced diligence on offshore licences automatically |
Hong Kong practice deserves a note. The working MSO pattern is an operating account in EMI infrastructure of the Airwallex class first, a bank account later, backed by a trading history. Lists of "friendly" banks in consultants' materials are unverifiable and guarantee nothing.
A category of its own is renting someone else's licence. It solves the account question fastest and creates precisely the problem that makes banks refuse: the operator becomes one more link in a nesting chain. The wider logic of the segment in 2026 is mapped in the overview of banks by jurisdiction.
Direct Settlement Access Instead of a Correspondent
The main structural shift of the last two years: a non-bank operator can increasingly do without a correspondent.
EU. Since October 2025 an EEA-authorised PI or EMI can open a settlement account in TARGET and TIPS. The Eurosystem policy announced on 19 July 2024 requires compliance with the same operational and technical requirements as for banks; there is no intraday credit, balances are capped, and the central bank will not open a safeguarding account.
United Kingdom. In its response to the discussion paper of 8 April 2025 the Bank of England tightened entry: an applicant must have been carrying on regulated activity for at least nine months, undergo a s166 assessment and pass stage gates (mobilisation and live-proving). At the same time the Bank is exploring whether non-bank PSPs might hold client funds in an RTGS account; today they cannot, even overnight. That is the most consequential open decision for UK fintech.
United States. On 20 May 2026 the Federal Reserve put a payment account out for comment — a stripped-down account for clearing and settlement. Under the Board's proposal, the closing-balance limit would be based on expected payment activity subject to a $1 billion maximum; the account would pay no interest, offer neither intraday credit nor discount-window access, and exclude FedACH. The proposal remained pending on 22 August 2026 after comments closed on 27 July; the Board meanwhile encouraged Reserve Banks to pause decisions on Tier 3 applicants under the Guidelines of 15 August 2022.
The legal backdrop is hard: on 31 October 2025 the Tenth Circuit confirmed that a legally eligible institution has no right to a master account — the words "may receive" in 12 U.S.C. 342 leave the decision to the Reserve Bank's discretion. The detail is in the Fed payment accounts explainer.
Where Money in an EMI Account Actually Sits
Money in an EMI or payment institution account is not a bank deposit. It is protected by segregation and the discipline of the specific institution, and the record on that discipline is poor: in Policy Statement PS25/12 of 7 August 2025 the FCA reports that firms that became insolvent between Q1 2018 and Q2 2023 showed an average shortfall of 65% against the funds owed to clients. The amount safeguarded by UK EMIs grew from roughly £11 billion in 2021 to £26 billion in 2024, with payment institutions holding around £6 billion.
The regulatory answer is CASS 15. Since 7 May 2026 an interim regime applies: internal and external reconciliations at least once on every reconciliation day, same-cycle remediation of any shortfall (including from the firm's own funds), a monthly REP027 return to the FCA, an annual safeguarding audit for everyone except firms safeguarding under £100,000 across 53 weeks (the first within six months of the period end, thereafter within four), and a resolution pack. The FCA has deferred the statutory trust until it has reviewed the interim regime, and any move to the end state depends on when and how the Treasury revokes the PSRs and EMRs.
For a client of the operator — a company or an individual — three questions read the risk on the funds-holding side:
- which bank and which country hosts the safeguarding account: that determines the applicable law on insolvency;
- one bank or several: concentration means a single account closure stops the whole business;
- whether the payment passes through intermediate providers: if so, the client sits at the end of a nesting chain, and in a stress scenario its funds will take the longest to untangle.
Keeping the Banking Relationship
Monitoring and RFIs
An open account is the start of observation. The bank compares actual flows with those declared at onboarding: corridors, average ticket, share of non-residents, counterparties. Any divergence becomes an RFI (request for information) about specific payments, customers or changes to the model. The speed and quality of RFI answers is, for the bank, the main measure of the operator's compliance maturity: an answer after two weeks, or one without documents, reads as a lack of control over the operator's own customers. Wolfsberg names the triggers for an out-of-cycle review, and for each of them it makes sense to tell the bank first: a new owner, a new or changed licence, an incident, adverse press, a new product or corridor, a new intermediary in the chain.
Closure Triggers
The typical reasons a bank exits repeat themselves: non-resident or crypto turnover above the declared level; an undisclosed nested customer; payments into sanctions-sensitive corridors; unsatisfactory RFI answers; supervisory pressure on the bank itself; a change in group risk appetite. The first four depend on the operator, the last two do not, and only diversification works against them. The mechanics of closure and the customer's rights are covered in the article on bank account closure.
Two Providers and an Exit Plan
At least two safeguarding providers in different groups is an operational-resilience measure and, for a UK institution, a question CASS 15.6.6G asks it to consider when choosing banks. In the EU the PSD3 compromise text requires concentration to be avoided where appropriate; in early September 2026 PSD3 was still an ongoing legislative procedure — the ECON committee approved the agreed text on 5 May 2026, the Council's first-reading position was outstanding, and the indicative plenary date in Parliament was 14 December 2026 — and until it is transposed EMI and PI safeguarding runs under PSD2 and EMD2. The second bank is worth opening and running live payments through before the first sends a notice: onboarding takes months, while a notice period is measured in weeks. The wind-down plan should cover a "bank closed the safeguarding account" scenario with a procedure for returning funds to clients; more in the article on the licensed operator's wind-down plan.
The Right to Reasons and to Notice
In the UK the Payment Services and Payment Accounts (Contract Termination) (Amendment) Regulations 2025 (SI 2025/688) came into force on 28 April 2026: for contracts entered into from that date, termination requires at least 90 days' notice, and the notice must contain an explanation sufficiently detailed and specific for the user to understand the reason; earlier contracts keep two months. The carve-outs are broad — inability to complete customer due diligence under the Money Laundering Regulations 2017, closure required by immigration law, reasonable suspicion of a connection to serious crime, a requirement by the FCA, the Treasury or the Secretary of State — and in those cases no termination notice is required at all, so neither the 90 days nor the explanation apply (reg. 51C). Where a notice is given, another legal requirement such as the tipping-off prohibition prevails over the duty to explain (reg. 51B(4)). For an operator being exited on risk appetite the reform is real; for one being exited on AML grounds it is worth close to nothing.
In the US the pendulum has swung harder. Executive Order 14331, "Guaranteeing Fair Banking for All Americans", of 7 August 2025 gave the banking agencies 180 days to strip reputation risk out of their guidance, 120 days to review supervised institutions for politicised or unlawful debanking up to fines and consent decrees, and directed Treasury to produce a counter-strategy. The Federal Reserve dropped reputational risk from supervision on 23 June 2025, and on 7 April 2026 the OCC and FDIC issued a final rule barring the agencies from criticising banks or pressing them to close accounts by reference to reputation risk, political or religious views or lawful business activity. The rule binds the regulator; the commercial decision to refuse still belongs to the bank.
If the Bank Refuses
The response to a refusal comes down to five steps.
- Written reasons. In the UK since April 2026 this is a right, and there is also the regulation 105 notification to the FCA; in the EU it is an argument citing Article 36 PSD2; elsewhere it is an argument to make in correspondence.
- The ground cited. "Risk appetite" is contested by switching provider; an AML ground effectively cannot be contested.
- Moving funds. Abruptly emptying an account in a panic is itself a SAR trigger.
- Removing the dependency. Direct payment system access, where it exists, removes the correspondent question entirely.
- One bank. Before 2026 a business plan resting on a single banking relationship was a design error; after the settlement-access reforms it signals unwillingness to fix that error.
For a crypto perimeter the design order runs further still: the structure is assembled from the far end — first establish which bank will carry the crypto flow and on what terms, and only then choose the zone and the licence type. The reverse order buys a licence with no settlement route behind it.
Q/A
Refusals and access rights
Why did the bank refuse an operator with a licence and a clean compliance record?
The decision is commercial. The US Treasury's 2023 De-risking Strategy names economics as the principal driver: the cost of diligence and monitoring on such an account frequently exceeds the revenue it produces. Nesting adds to it: behind one customer the bank sees an unknown number of agents and their customers. An appeal achieves almost nothing here. What works is choosing a provider for whom operators are the core product, and disclosing the chain before being asked.
Is a bank obliged to open an account for a payment institution?
Nowhere is there a direct duty to open a particular account. In the UK, regulation 105 of the PSRs 2017 requires banks to give payment institutions, EMIs and applicants for authorisation objective, non-discriminatory and proportionate access, and a bank that refuses gives reasons to the FCA. In the EU, Article 36 PSD2 plays the same role, but in 2022 the EBA found it was applied unevenly. In the US, the 2005 interagency guidance requires MSBs to be assessed on risk and says expressly that a bank is not expected to become the industry's de facto regulator.
Documents and account architecture
What goes into the document pack for the bank?
A Wolfsberg questionnaire (the CBDDQ for respondent banks or the FCCQ), AML/CFT and sanctions policies, an EWRA from the last 12 months, an independent audit report with a remediation plan, a flow-of-funds map showing every account, a list of correspondents and payment partners, a description of customer segments and the nested strategy, the travel rule procedure, the MLRO's CV and authority, a description of safeguarding and the wind-down plan. The bank may also sample-test customer files.
Can client funds be held in a central bank account?
In the euro area, no. The ECB decision of 27 January 2025 and the Eurosystem policy bar central banks from offering safeguarding accounts to non-bank PSPs and crypto-asset providers: a TARGET or TIPS account serves settlement only, capped at twice the peak of outgoing transfer orders over 12 months. The UK's regulation 23 formally allows funds to be placed with the Bank of England, but in practice the Bank is only exploring the option for RTGS, and as at August 2026 there is no decision.
What is the danger of a sub-account at an EMI instead of an own bank account?
The operator becomes a customer's customer and its funds part of the EMI's safeguarding pool. The EMI's bank sees only the aggregate flow and, if concerns arise, closes the entire pool. Since 30 June 2026 a UK regulated person opening a pooled account must understand its purpose and assess the risk, so the EMI will ask the operator the same questions a bank would. The arrangement is acceptable for a start; at scale an own safeguarding account is needed.
Regulatory change
What do the 2025–2026 debanking reforms actually change?
In the UK, from 28 April 2026: at least 90 days' notice and a duty to give a sufficiently detailed and specific explanation, for contracts entered into from that date. But the carve-outs cover failed customer due diligence, suspected links to serious crime and regulatory direction — which is most real-world fintech account closures. In the US, Executive Order 14331 and the OCC/FDIC final rule of 7 April 2026 removed reputation risk from the supervisory toolkit: that binds the regulator, but obliges no bank to open or keep an account.
How are VASPs and CASPs banked after MiCA and the GENIUS Act?
A licence improved the negotiating position without settling it: AMLR (Regulation (EU) 2024/1624), applying from 10 July 2027, sets in Article 37 an enhanced diligence regime for cross-border correspondent relationships between crypto-asset providers and third-country respondents.
In the EU a payments requirement has been added: according to the EBA the transition period for CASP activity in e-money tokens ended on 2 March 2026, and that activity now needs PSP status (a national authority may let a CASP that filed its PSD2 application in time keep operating pending the decision); MiCA's own grandfathering for providers operating under national regimes expired on 1 July 2026.
In the US the GENIUS Act, signed on 18 July 2025, pulls payment stablecoin issuers under federal rules — the OCC put its proposed requirements out for comment on 25 February 2026 and on 22 June 2026 proposed BSA and sanctions compliance rules for issuers; the Act itself takes effect no later than 18 January 2027, or 120 days after final rules if sooner. The OCC's five conditional approvals of December 2025 show that some crypto firms are seeking limited-purpose national trust bank charters; on the OCC's 31 July 2026 list four of the five appear as active trust banks, and Ripple is absent.