Chat with us, powered by LiveChat

Crypto-Friendly Banks: An Honest Assessment

A “crypto-friendly bank” in August 2026 is a licensed financial institution that will underwrite virtual-asset activity: a VASP, CASP or equivalent licence (or a written exemption), a source-of-funds file that reconstructs fiat and chain, and a Travel Rule record a reviewer can sample. Retail listicles score banks on whether a debit card still funds a licensed exchange. That is a consumer rail. The corporate underwrite is the file.

Nataly Medici
Nataly Medici
Managing Partner and CEO

UAE company formation and licensing starts with that distinction. Jurisdiction choice without a banking logic leaves you with a certificate and no operating account. This page is a scoring sheet you can update when a supervisor or a bank changes the perimeter.

What does “crypto-friendly bank” mean in August 2026?

Search results treat the phrase as a personality test. A bank “likes Bitcoin” if it lets a retail customer ACH to Coinbase, or if a neobank app lists tokens next to a current account. For a VASP, an OTC desk, a custodian or a PSP that ramps to chain, the underwrite is different. The institution has to accept that your customers move value, that some of those customers are themselves VASPs, and that residual risk on those flows sits with the bank in the same way correspondent risk sits with a respondent’s bank.

Ksenia Babochkina, Commercial Director at Medici Expert, put the refusal reason on the firm’s digital-assets page: “Crypto companies don't get rejected by banks for being crypto companies. They get rejected for not being able to explain themselves clearly.”

The explanation is a file. Licence status. Beneficial owners. Expected volumes by corridor and by asset. Source of funds and source of wealth. Travel Rule payloads. Sanctions and wallet-screening tickets. An independent test of the models. A bank that will not read that file is not underwriting VA activity, whatever its marketing page says about digital assets.

A second split sits inside “friendly”. Some institutions will hold the company’s own operating cash and payroll after they see a licence. Fewer will hold client money. Fewer still will let nested third-party VASPs transact through the account. CBUAE’s licensed-financial-institution guidance treats those as different products. An EU electronic money institution is a different product again: an IBAN without a deposit. If you collapse those products into one ranked list, you will shop the wrong permission.

Nataly Medici, Managing Partner and CEO, wrote the same stack on that digital-assets page: “Entering a regulated market is not just about registering a company or applying for a license. Your entity, business model, banking setup, compliance framework and jurisdictional logic must work together from day one.”

The scoring sheet below is how a bank tests whether that stack exists.

Which file does a bank sample when it underwrites VA activity?

A bank that takes a VASP as a customer takes residual risk on that VASP's clients, as a correspondent takes residual risk on a respondent. CBUAE's VA/VASP guidance for licensed financial institutions uses that analogy. The PDF is guidance, not a VASP statute. It tells the bank what to sample so it can show the Central Bank it met the AML-CFT Decision. FATF Recommendation 15 brings VASPs inside Recommendations 10 to 21. Recommendation 16 puts originator and beneficiary information on the transfer. A UAE reviewer in August 2026 opens Cabinet 134 Article 36, the CBUAE Virtual Assets Travel Rule, and VARA III.G for a Dubai VASP.

FATF Recommendation 15 and the June 2025 Rec. 16 overlay

Recommendation 15 and its Interpretive Note apply the FATF preventive measures to virtual assets and VASPs. Occasional CDD for VASPs attaches at USD/EUR 1,000 in that overlay. Recommendation 16 requires originating and beneficiary institutions to obtain, hold and transmit originator and beneficiary information on transfers, including virtual-asset transfers. FATF agreed revisions to Recommendation 16 at the June 2025 Plenary, with national effect by the end of 2030 and an assessment-methodology annex on 28 October 2025. Those revisions are overlay, not UAE law in August 2026. A UAE licensed bank samples Cabinet 134, the CBUAE Virtual Assets Travel Rule and VARA Rule III.G this year. A correspondent outside the UAE will still sample FATF.

UAE operating instruments a bank reviewer will open

Cabinet Resolution No. 134 of 2025 Article 36 requires a licence, registration or listing to conduct VASP activity from the State. The originating VASP obtains, retains and transmits originator name, account or VA wallet, and residential or business address, plus beneficiary name and account or wallet. The beneficiary VASP retains. VASPs take financial-institution targeted-financial-sanctions duties. Financial institutions that send or receive virtual-asset transfers for a customer inherit the same transfer clauses. The bank samples that payload.

The CBUAE Virtual Assets Travel Rule, In-Force on the Central Bank rulebook as of 18 August 2026, adds operating cuts. Article 1(4) bars execution to an unregulated VASP. Article 1(10)–(11) sets beneficiary identity verification at daily aggregated AED 3,500. Article 3 requires extra identification and source-of-funds verification before send or receive with an unhosted wallet, and a decline if originator data is missing on outbound. Article 5 bars execution of a Privacy Token. Crypto compliance in 2026 maps the UAE stack for operators. This page maps what the bank takes from it.

VARA’s Compliance and Risk Management Rulebook, file VARA_EN_123_VER20250519, effective 19 June 2025, puts Travel Rule compliance through federal AML-CFT laws (III.G.1) and requires a Dubai VASP to handle deposits, withdrawals, unhosted VA wallets and anonymity-enhanced transactions (III.G.7), with a sunrise plan at licensing (III.G.8). AML/CFT policy and monitoring work is the pack that makes those rules visible. A bank that cannot see the sunrise list, the unhosted-wallet EDD memo and the privacy-token decline log has no file to underwrite.

How do UAE licensed banks treat VASP customers?

CBUAE tells licensed financial institutions to treat VASP onboarding as a named control. Section 3 of the VA/VASP guidance splits administrative accounts from transactional accounts that hold client funds. Staff and revenue accounts do not require a non-objection request. Client-money accounts must sit in a protected escrow: daily VASP reconciliation, monthly auditor review, and ring-fencing against withdrawals other than client-directed payment. For each VASP the bank still sends the Central Bank a case-by-case non-objection with a compliance attestation. An unlicensed VASP sits outside that path until a licence or a bank-addressed non-objection certificate is on file.

Administrative accounts versus client-money escrow

Section 3.1 of the guidance lets the licensed financial institution open operational accounts for a VASP without a Central Bank non-objection: staff and administrative expenses, and accounts for revenue from services the VASP rendered. That is payroll, rent and the company’s own fees. It is not client fiat. Founders who celebrate “we got a UAE bank account” often hold this product. It will not clear customer deposits.

Section 3.2 is the client-money product: a protected escrow, client deposits in, ring-fencing against withdrawals other than client-directed payment, daily VASP reconciliation, and a monthly agreed-upon-procedure review by the VASP’s external auditor. The bank may move funds only for settlement, refund and equivalent purposes. UAE courts have jurisdiction over dirham transactions (section 3.3). Controls sit in written agreements and in the bank’s own policy (section 3.4).

Section 3.5 still requires a case-by-case non-objection with a compliance attestation for VASP accounts the Central Bank treats as in-scope. Confirm the live request channel with the bank. The PDF is guidance, not a gazette form. The split between operating cash and client money is the part a founder cannot negotiate away.

If an existing customer meets the VASP definition but has no valid UAE licence, or the licence has lapsed, been revoked or been suspended, the guidance tells the bank to restrict activity until a licence or a bank-addressed non-objection certificate is on file. Nested third-party VASPs sit in the correspondent-style bucket and take enhanced due diligence. If your product is “we bank other exchanges”, say so in the first meeting.

Unlicensed VASPs and the joint guidance

The Joint Guidance on Combating the Use of Unlicensed Virtual Asset Providers in the United Arab Emirates is a public document from the Central Bank with SCA, VARA, DFSA, FSRA and the Ministries of Justice and Economy. NAMLCFTC issued the accompanying notice on 6 November 2023. Licensed financial institutions, DNFBPs and licensed VASPs must factor unlicensed providers into risk assessments and treat wilful blindness as a control failure. Unlicensed activity from the State attracts administrative and criminal penalties on the entity, owners and senior managers.

A bank that underwrites VA activity will ask for the licence number and the supervisor, then check a public register: VARA, FSRA, DFSA, SCA or CBUAE in the UAE; a home-state CASP register under MiCA; the FCA cryptoasset register in the UK, which is not a banking permission. If you cannot point at a register line, CBUAE Virtual Assets Travel Rule Article 1(4) already bars counterparties from executing to you as an unregulated VASP.

Where do EMI and PSP accounts sit relative to a commercial bank?

Founders use "bank" for any IBAN that moves euros. An electronic money institution and a payment institution hold payment accounts, not deposits. Directive 2009/110/EC Article 6(2) bars EMIs from taking deposits or other repayable funds from the public. Article 6(3) requires them to exchange those funds for electronic money without delay. PSD2 Article 18(2) limits payment institutions to payment accounts used exclusively for payment transactions. Article 18(3) states that funds received for payment services are not a deposit under CRD Article 9. A VASP that needs client-money escrow, a nostro, or a credit line is shopping a different permission.

What an EMI may hold

An EMI issues electronic money and runs payment services. It safeguards user funds by segregation into a credit-institution account or into secure low-risk assets, or by an insurance or guarantee structure. EMD2 Article 6 already says those funds are not deposits. An EMI can still be the right rail for multi-currency payments, acquiring and, where its licence allows, fiat ramps next to a VASP. It will not replace a credit institution when a supervisor asks who holds client fiat as deposits.

A payment institution is narrower: payment accounts used exclusively for payment transactions. Interest on the float, lending from user funds, or a promise that the IBAN is a bank account is a perimeter breach. Licensing and company formation treats EMI and PSP routes as separate from a VASP licence. Shop both if the product needs both.

What a credit institution may hold

A commercial bank or other credit institution takes deposits and, subject to its licence, may hold client money in the escrow form its supervisor described. In the UAE that form is CBUAE guidance section 3.2 plus the non-objection in section 3.5. In the EU the credit institution sits under CRD and the Deposit Guarantee Schemes Directive.

Switzerland publishes a VA banking perimeter: FINMA’s 26 August 2019 announcement licensed SEBA Crypto AG (Zug) and Sygnum AG (Zurich) as banks and securities dealers; the current authorised-institutions list names AMINA Bank AG (Zug) and Sygnum Bank AG (Zürich) as banks. That is a register fact, not a recommendation to open those two names. MAS Guidelines PS-G02 (17 January 2022) apply to Singapore banks that provide digital payment token services and limit public promotion of DPT trading. OCC Interpretive Letter 1183 (7 March 2025) rescinded IL 1179’s prior non-objection and reaffirmed IL 1170, 1172 and 1174 for national banks and federal savings associations; IL 1184 (7 May 2025) confirmed buy-and-sell of custodied assets at the customer’s direction. Permissible activity is not a published appetite for your VASP.

Scoring sheet: what the bank underwrites, the evidence, and the common fail (August 2026)

An updateable map, dated 18 August 2026. Categories of institution and product, not a ranking of brands. Confirm every category against the live register and the institution’s current onboarding policy before you file. Fees, minimum balances and indicative 6–8 weeks clocks (indicative market range, not a Medici quote) sit outside this map; they move with the file.

UAE CBUAE-licensed bank, VASP client-money / escrow

Underwrites client fiat in a protected escrow; settlement and refund only; UAE court jurisdiction on AED. Evidence: VASP licence or NOC addressed to the bank; CBUAE non-objection pack; escrow agreement matching guidance 3.2(a)–(f); daily reconciliation; monthly AUP auditor letter; UBO, SoF/SoW, Travel Rule and wallet-screening samples. Common fail: asking for a pooled operating current account to hold customer deposits; no daily rec; auditor letter missing; nested VASPs undisclosed.

UAE CBUAE-licensed bank, VASP operating / admin only

Staff, rent, own-revenue cash. No client money. Evidence: licence; corporate KYC; expected operating spend; attestation that client funds will not land here. Common fail: routing customer deposits into the admin account after opening; activity codes that still look like VASP client flows.

UAE licensed VASP with nested third-party VASPs

Correspondent-style residual risk on downstream VASPs. Evidence: EDD on each nested VASP; licence status of those VASPs; CBUAE VA Travel Rule Art. 1(4) counterparty check; sunrise list (VARA III.G.8 if Dubai). Common fail: “We only bank licensed firms” with no nested map; P2P or unhosted flows hidden in OTC chats.

EU electronic money institution or payment institution

Payment accounts and e-money. Not deposits. Safeguarding, not DGS. Evidence: home-state EMI/PI authorisation; safeguarding method; programme limits; VASP or CASP status of the applicant if VA ramps sit on the account. Common fail: calling the IBAN a bank account in the board memo; expecting deposit insurance; nested VASP flows the EMI never appetite-checked.

Swiss FINMA-licensed bank with a published VA perimeter

Deposits plus, where the licence covers it, VA custody and securities-dealer activity inside the Banking Act / FMIA stack. Evidence: FINMA register line (bank vs securities firm vs Art. 1b FinTech); institutional-client eligibility; Travel Rule and custody controls as FINMA applied them at licensing. Common fail: treating a Swiss securities firm or a FinTech-licence entity as a bank; retail onboarding into an institutional book.

Singapore MAS-supervised bank or DPT provider

Bank products plus, if licensed for it, DPT services under the Payment Services Act; PS-G02 conduct on public promotion. Evidence: MAS licence or bank status; DPT activity permissions; no public-promotion breach; SoF on fiat legs. Common fail: using a retail comparison-site “DBS is crypto-friendly” line as the file; promoting DPT services in a way PS-G02 bars.

US national bank or federal savings association (OCC perimeter)

Bank-permissible crypto-asset custody and related activities per IL 1170/1172/1174 as reaffirmed by IL 1183; buy/sell at customer direction per IL 1184. Evidence: charter; BSA/AML programme; custody procedures; OFAC and Travel Rule where a transfer is in scope; third-party / sub-custodian risk file. Common fail: equating OCC permissibility with a published appetite for your VASP; confusing retail debit-to-exchange with corporate underwriting.

Unlicensed or offshore VASP shopping a fiat account

In the UAE, restricted until a licence or bank-addressed NOC exists. Counterparties barred from executing VA transfers to an unregulated VASP (CBUAE VA TR Art. 1(4)). Evidence: none that substitutes for a licence. A foreign register line does not cure Article 36(1) if you conduct VASP activity from the State. Common fail: “We will licence later”; forged or lapsed licences; using an offshore company as the VASP without a supervisor.

Ordinary UAE company with no VA activity

Standard corporate current account. Separate process from this page. Evidence: incorporation, IDs, proof of address, business plan without VASP activity. Common fail: mixing personal exchange cash-outs through the company account until the bank re-rates the file as undeclared VA.

Update the map when Cabinet 134 article numbers, VARA rulebook versions, CBUAE guidance, OCC letters or MAS guidelines change. Do not update it by pasting a new “top 10” from a comparison site.

What opens an account, and what ends the file?

Opened files share a shape. The legal entity matches the activity on the rail. The licence matches that activity on a public register. Beneficial owners have a source-of-wealth memo that survives a second reviewer. Expected activity is written in numbers: corridors, assets, peak size, nested VASP, unhosted wallet. Source of funds on first credits is documented before the credit. Travel Rule messages, or unhosted-wallet EDD, sit in a ticket the bank can sample. Sanctions and wallet screening have owners, hop depth and a fail-closed rule. Independent testing exists as a dated memo. For UAE client money, escrow mechanics and the Central Bank non-objection sit in the same pack.

Refused files share a different shape. Incorporation says “general trading” and the website is an exchange. The licence is “in process” with no application number. The UBO is a nominee with no wealth file. First fiat is cash or a third-country personal account. Nested VASPs live in chat, not in the chart. The founder wants client money in an ordinary current account. Privacy-token execute bans and unhosted-wallet EDD are missing from the procedure. Each of those is a hole in the underwrite.

A retail debit-card purchase on a licensed exchange does not open this file. US and UK PAA questions (“Is Chase crypto friendly?”, “Is Monzo a crypto-friendly bank?”) are about that consumer rail. A VASP that copies those answers into a board deck has not started onboarding.

How long does onboarding take, and what “open” includes?

Medici Expert’s live accounting-and-tax page, as of 18 August 2026, publishes 2–4 weeks for standard corporate accounts and 6–8 weeks for high-risk crypto and fintech files. Those are planning ranges, not a Central Bank or OCC SLA. A VASP client-money file that needs a CBUAE non-objection or nested-VASP EDD can run past the high-risk band. An incomplete pack restarts the clock each time compliance sends the file back.

For an operating account, “open” means the company can pay rent, payroll and vendors, and can receive its own fees, inside the activity the bank accepted. For a client-money escrow, customer fiat lands in the ring-fenced account and leaves only on a client instruction the mandate allows. For an EMI, payment transactions run inside the programme with safeguarding, and nobody calls the balance a deposit. An account number that blocks every VASP counterparty is an operating account with a VA exclusion. Score it that way.

The ordinary process for a UAE company that is not in virtual assets follows the standard corporate CDD path — document lists, interviews, and common refusal reasons differ from the VA-specific assessment. This scoring sheet covers the VA underwrite; close it for a plain trading or services account.

An offshore company sold with “a bank account included” is a different product. The pack rarely names the institution, the permission, or whether client money is in scope. Treat that promise as a separate assessment. A BVI or Seychelles vehicle can sit in a group that also holds a licensed VASP. On its own it is not the licence a UAE bank or an EU EMI will underwrite for VA client flows.

How should you read a category map without a ranked list?

Appetite moved in public in 2023 and the perimeter moved again in 2025. Silvergate Capital announced on 8 March 2023 that it intended to wind down operations and voluntarily liquidate Silvergate Bank. The Federal Reserve, with California’s Department of Financial Protection and Innovation, issued a consent order on 1 June 2023 to govern that self-liquidation. NYDFS took possession of Signature Bank on 12 March 2023 and appointed the FDIC as receiver; the FDIC established Signature Bridge Bank, N.A. the same day. Signature had a public digital-asset deposit book. The NYDFS internal review is a liquidity and possession record, not a finding that “crypto killed the bank”. Both names left a published perimeter. Correspondent appetite after those exits is why a VASP now walks in with a licence and a Travel Rule file.

The 2025 OCC letters reopened permissibility for US national banks on custody. Permissibility is not a queue number at a named bank. MAS PS-G02 assumed some Singapore banks would provide DPT services and then limited how they promote them. FINMA’s 2019 licences put VA activity inside a banking licence. CBUAE’s 2023 guidance, still the live PDF in August 2026, split admin cash from client escrow and demanded a non-objection. Those are category facts. They survive a rebrand. A ranked table of ten logos does not.

Revisit the sheet when you add nested VASPs, unhosted-wallet deposits, a privacy asset, or a move of client money from an EMI safeguard into a bank escrow. Each of those is a new underwrite. The search bar will still say “crypto-friendly”. The bank reads the file.

FAQ

What is a crypto-friendly bank in 2026?

A licensed financial institution that will underwrite virtual-asset activity with a licence or documented exemption, a reconstructable source-of-funds file, and a Travel Rule (or unhosted-wallet EDD) record a reviewer can sample. A retail current account that still funds a licensed exchange is a consumer rail. Score the two products separately.

Which bank is the most crypto-friendly?

There is no stable public ranking that a supervisor will accept. Institutions publish perimeters (OCC letters, FINMA register lines, CBUAE guidance, MAS PS-G02) and then take or refuse individual files. A comparison-site “top 10” mixes EMIs, challenger apps and credit institutions. Use the category sheet above and confirm the live register.

Can an EMI replace a corporate bank account for a VASP?

An EMI can run payments and hold e-money. Directive 2009/110/EC Article 6 bars it from taking deposits. PSD2 Article 18 says payment-institution funds are not deposits. If you need client fiat in a bank escrow, a nostro, or deposit-guarantee treatment, you still need a credit institution. Many groups hold both.

Do UAE banks need Central Bank non-objection for VASP accounts?

CBUAE’s VA/VASP LFI guidance, section 3.1, lets licensed financial institutions open VASP operating and staff accounts without a non-objection request. Section 3.2 sets escrow conditions for client-money accounts. Section 3.5 still requires a case-by-case non-objection with a compliance attestation for VASP accounts the Central Bank treats as in-scope. Confirm the live process with the bank. The PDF is guidance, not a gazette form.

How long does a crypto business bank account take to open?

Medici Expert’s published ranges as of 18 August 2026 are 2–4 weeks for a standard corporate account and 6–8 weeks for high-risk crypto and fintech files. A VASP client-money file that needs CBUAE non-objection or nested-VASP EDD can exceed that band. Incomplete SoF or Travel Rule samples restart the clock.

Will a bank open an account for an unlicensed VASP?

In the UAE the LFI guidance tells the institution to restrict activity until a valid licence or a bank-addressed non-objection certificate is on file. The CBUAE Virtual Assets Travel Rule Article 1(4) bars execution to an unregulated VASP. Joint guidance from CBUAE, SCA, VARA, DFSA and FSRA treats wilful blindness toward unlicensed providers as a control failure.

Does allowing debit-card buys on an exchange make a bank crypto-friendly?

That answers a retail PAA question. It does not answer whether the same institution will hold VASP client money, accept nested VASPs, or file a CBUAE non-objection. Score consumer rails and corporate underwrites on different rows.

What evidence does a bank sample on Travel Rule and source of funds?

Licence line on a public register. UBO and SoW. Expected corridors and assets. SoF on first credits. Originator and beneficiary payloads under Cabinet 134 Article 36 and the CBUAE Virtual Assets Travel Rule (or the unhosted-wallet EDD in Article 3). Wallet-screening tickets with hop depth. Privacy-token decline logs under Article 5. Independent testing of the models. For Dubai VASPs, VARA III.G.7–8 on top of the federal floor.

Connect with our experts

Get full clarity on licensing, compliance and structuring before you spend time and budget on the wrong move.

Book a Free Call

Ready to build a structure that actually works?

Whether you are launching a fintech company, applying for a license, entering the UAE, issuing a token or preparing for regulatory review — we can help you choose the right path before costly mistakes happen.

Book a Free Call