Chat with us, powered by LiveChat

Why Banks Reject Crypto Companies and How to Get Approved

September 7, 2026

A bank's compliance desk does not read a crypto company application the way a founder reads their own pitch deck. The analyst runs a risk-based decision tree from the first document in the stack, and most files stall at the same four or five junctions.

Nataly Medici
Nataly Medici
Managing Partner and CEO

Understanding that sequence before submitting — not after a refusal — is the practical difference between a six-to-eight-week opening and a recorded denial that follows the company to its next attempt.

Below is the decision chain a bank's compliance team runs when a VASP application lands on the desk, and what the file must contain to move through each gate.

How a bank's compliance desk reads a VASP application

The first question the analyst asks is not "do we like crypto?" It is whether the file permits a risk assessment to begin at all. Cabinet Resolution 134/2025 Article 14, the operating AML regulation in the UAE as of December 2025, requires a licensed financial institution to decline the relationship if customer due diligence cannot be applied. That clause is the first filter. A file that arrives incomplete — missing constitutional documents, a UBO chain that stops at a holding company, no description of what the business actually does — does not fail because the bank dislikes the sector. It fails because the analyst cannot open a case file.

The second layer is risk classification. Once the identity papers are in order, the desk maps the application against internal risk appetite and the regulatory framework governing virtual-asset counterparties. The CBUAE has published guidance for licensed financial institutions on risks related to VAs and VASPs, which sits live on the central bank's website as of August 2026. That guidance distinguishes between two types of VASP relationships: an administrative account (operating costs, staff payroll, no client money) and a transactional account through which the VASP moves client funds. The transactional category carries materially higher compliance obligations. A VASP applying for a full operating account that does not acknowledge this distinction in its file gives the analyst no way to risk-score the relationship accurately.

The third layer is sector appetite. A bank may complete CDD successfully and still decline because the sector sits outside its approved risk appetite. Appetite decisions are internal and change without announcement. Asking whether the sector is in scope before the formal application is a straightforward first step that saves substantial time.

What the analyst checks in the first thirty minutes

The analyst's first pass runs through five documents: the constitutional file, the ownership chart, the licence or registration evidence, the AML policy, and the business description. Each one either advances the case or creates a hold. Constitutional documents establish the legal entity and its signing authority. The ownership chart must walk to a named natural person at the 25-percent threshold, per Cabinet 134/2025 Article 10. The licence or registration confirms what the VASP is legally permitted to do. The AML policy tells the desk whether the applicant understands the regulatory obligations their sector attracts. The business description — products, transaction flows, client types, volume ranges — lets the analyst map expected activity against later transaction monitoring. A file that passes all five in the first review moves to extended diligence. A file that fails any one of them stalls at that point until the gap is closed.

The internal risk-scoring model

CBUAE guidance on VA and VASP risks instructs licensed institutions to treat the VASP relationship through a correspondent-banking lens: the bank is underwriting exposure to the VASP's own customers and their transaction flows. This framing explains why banks ask for information that founders consider excessive. Counterparty lists, wallet-screening provider names, transaction monitoring tooling, the jurisdictions the VASP serves — these are inputs to the bank's own residual risk calculation. A VASP that pre-answers each of these questions in a covering note removes the conditions for multiple back-and-forth requests.

Business model clarity: what "clear" means to a KYB analyst

A KYB analyst has a narrow definition of "clear." The business model is clear when the products match the licence, the licence matches the company objects, the website matches the products, and the transaction flows match the expected-activity note. When any element disagrees with another, the analyst cannot finalise the risk profile without resolving the conflict. Founders who launched with one product and pivoted without updating the licence, or who describe their offering in marketing language rather than regulatory categories, create mismatches the analyst cannot close without asking.

Products and licensed activity

VARA licences cover specific VA activities: exchange, broker-dealer, lending, management and investment, transfer and settlement, custody. ADGM FSRA and DIFC DFSA categorise VA permissions at a similar level of granularity. Each licensed activity defines the money flows the bank expects to see in that account. An exchange account shows inbound from retail customers, outbound to liquidity providers and settlement venues. A custody account shows asset-transfer logic distinct from retail order flow. A VASP that describes itself as an "all-in-one digital asset platform" without specifying which permissions it holds, and which flows correspond to which, is asking the analyst to guess. The analyst stops and asks. If the answer arrives in ten days, the timeline extends by at least ten days.

Website, product copy, and licence alignment

The bank's compliance team will open the applicant's website the same day the application arrives. When the product copy advertises services that fall outside the licensed category, or refers to services in jurisdictions where no permission exists, the mismatch becomes a material question that pauses the file. A VASP that holds a UAE VARA licence for exchange services but whose homepage promotes staking products that VARA has not approved, or asset management services for which no separate licence exists, will be asked to explain the discrepancy before the account review can proceed. Updating or adding a scope note to the website before application is simpler than managing a back-and-forth while the account sits on hold.

AML/CFT policy: what a bank expects to see

The bank is not looking for a generic AML document. It is looking for a policy that reflects the VASP's actual risk exposure — the client types the company onboards, the transaction categories it processes, the jurisdictions it operates in, and the escalation logic when those risk factors converge. A policy that could have been written for any financial company in any industry signals to the analyst that compliance has been outsourced at a surface level without genuine implementation.

The FATF Guidance on Virtual Assets, updated through 2023, sets out the risk factors banks assess when taking on VASP counterparties: whether the VASP is licensed, whether it applies CDD to its own customers, whether it has implemented the Travel Rule, and whether it operates in jurisdictions with AML/CFT deficiencies. A bank that takes on a VASP relationship without addressing these factors faces scrutiny in its own AML examination. The VASP's compliance file is part of the bank's own compliance evidence.

What the policy must contain

A bank-readable AML/CFT policy covers: the risk appetite statement; the CDD procedure for individual clients including identity verification method; the KYB procedure for corporate clients including beneficial ownership chain; the transaction monitoring logic including on-chain screening tool and rule set; the sanctions screening procedure; the SAR filing process; and the record-keeping schedule. Each section should reflect what the company actually does.

The CBUAE guidance for LFIs on CDD and record-keeping, effective November 2025, instructs banks to review the compliance controls of VASP counterparties before establishing the relationship. A policy that names no specific screening tool, identifies a compliance officer not present in the corporate documents, or sets thresholds inconsistent with Cabinet 134 will attract questions the VASP should have answered in the document itself.

Who owns compliance in the file

Banks pay attention to corporate governance in the compliance file. The identity and qualifications of the MLRO or compliance officer matter because they are a signal about whether the policy is operational or decorative. A founder who lists themselves as the MLRO while also appearing as CEO, CTO, and primary shareholder is not necessarily a disqualifying structure at early stage — but it invites questions about segregation and oversight that the file should address proactively.

Licence status: how the risk tier changes

Whether the VASP holds a licence, has applied for one, or is operating without any regulatory status produces materially different outcomes in the bank's risk-scoring model.

A licensed VASP — one holding an active VARA permission, ADGM FSRA licence, DIFC DFSA licence, or equivalent — enters the review with a baseline compliance status established by the regulator. The licensing authority has verified the applicant's ownership structure, approved the business plan, reviewed the AML framework, and confirmed the MLRO. The bank's CDD still proceeds in full, but the risk classification starts from a lower floor. The licensing supervision provides a secondary layer of comfort that would otherwise have to be reconstructed entirely from the applicant's own documents.

VARA-licensed versus pending versus unlicensed

A VARA-licensed VASP can demonstrate current standing through VARA's public register. The bank can confirm the permission type, the licence date, and the licensed entity name independently. That independent verifiability is different in kind from a VASP that provides a pending-application reference number or a letter from a consultant saying it "is in the process of applying." Pending status is not a regulatory permission. It creates an open question — whether the licence will be granted, when, under what conditions — that the bank then has to carry in the risk file. Some banks will proceed with pending applications under enhanced diligence. Others will not take the application until the licence is confirmed. Asking this question before investing in the full document pack saves several weeks.

An unlicensed VASP operating in a jurisdiction that requires licensing — and the UAE requires licensing under the VARA regime for VA activities conducted in or from Dubai, with ADGM and DIFC covering their respective financial free zones — is in a category that most banks will not service. The Joint Guidance on Combating the Use of Unlicensed Virtual Asset Providers in the UAE, issued by CBUAE, SCA, VARA, DFSA and FSRA in 2023, makes explicit that UAE licensed financial institutions should not service unlicensed VASPs. A VASP that argues exemption because it serves offshore clients, or that offers a mainland trade licence as a substitute for a VA licence, will find the bank's compliance desk reads the same guidance.

Jurisdiction of licensing and bank appetite

The jurisdiction of licensing also affects the risk tier. A VARA licence positions the entity within the UAE regulatory perimeter and makes the licensing authority accessible to the bank's own regulators. A licence from a jurisdiction the FATF has identified as having strategic deficiencies requires the bank to apply enhanced diligence and document why it continues the relationship despite the elevated risk. That diligence is possible but raises the floor for what the bank needs to see in the VASP's own compliance framework.

Travel Rule controls: why banks ask and what evidence they want

The Travel Rule requires VASPs to collect and transmit originator and beneficiary information on virtual-asset transfers above prescribed thresholds. In the UAE, Cabinet Resolution 134/2025 Article 36 operates alongside the CBUAE Virtual Assets Travel Rule (In-Force, August 2026). The VARA Compliance and Risk Management Rulebook (VER20250519, effective 19 June 2025) addresses Travel Rule implementation in section III.G, including unhosted wallets and anonymity-enhanced transactions.

Banks ask about Travel Rule implementation because it indicates whether the VASP can distinguish between transfers it can service and transfers it cannot. A VASP that describes its Travel Rule policy as "pending implementation" gives the bank no way to categorise the risk in the account's expected flows.

What the evidence pack looks like

The Travel Rule section of the application file typically includes: the name of the VASP's Travel Rule solution provider; a description of the counterparty-VASP verification process; the threshold at which obligations are triggered under the CBUAE rulebook; and the procedure for unhosted wallets, which both the VARA Rulebook and the CBUAE Travel Rule address with enhanced diligence requirements. A VASP that can produce this section in specific prose — rather than a statement that it "complies with applicable laws" — removes a category of questions that often stalls applications for weeks.

Source of funds and counterparty risk

The bank needs to understand where the VASP's own capital came from and what kind of transaction counterparties the account will interact with. These are related but distinct questions. Source of funds for the company's initial capital — founder contributions, seed investment, grants — is documentation of the money that will first credit the account. The standard pack includes prior bank statements showing the outgoing wire, share-subscription agreements, investor documentation, or converted crypto holdings traced from fiat origin through the venue and into the company account.

Counterparty risk is forward-looking. The bank asks the VASP to describe the categories of institutions it transacts with: retail customers, institutional clients, other VASPs, fiat off-ramps, exchange venues. For each category, the bank wants to understand the VASP's own onboarding controls. A VASP that processes withdrawals to unhosted wallets without a documented EDD procedure, or that sends to counterparty VASPs without verifying their FATF-compliance status, creates a residual-risk trail that lands back in the bank's own compliance file.

High-risk transaction categories

CBUAE guidance on VA and VASP risks specifically flags several transaction categories that banks treat as elevated risk in VASP accounts: peer-to-peer transactions with unhosted wallets, privacy tokens, mixers, and flows through jurisdictions with high-risk AML ratings. A VASP that processes any of these categories needs a documented explanation of how it manages that exposure — the on-chain screening tool used, the escalation procedure when a flagged address appears, and the SAR process if the transaction cannot be resolved. Absence of this documentation does not mean the bank will decline; it means the bank will ask, and the file will wait.

Corporate substance and governance

Thin substance is a recurring factor in VASP rejections that founders routinely underestimate. Banks look at the VASP's physical and operational presence: a registered address that maps to a real office, a compliance officer with verifiable credentials, and a management structure capable of genuine AML oversight.

A VASP incorporated in the UAE but whose actual operations and decision-making sit elsewhere — with the UAE entity used only as a regulatory address — is likely to produce a substance question. UAE licensed banks operate within the UAE AML framework, which ties CDD to the entity's actual activity and control structure. When the licence address is a flexi-desk and the only UAE-resident director also performs the MLRO role while running operations from abroad, the file has a substance problem no additional document can resolve.

What "governance" means to the compliance desk

The analyst reads governance through a narrow lens: who has authority to bind the company, who supervises compliance, and who the bank calls when a transaction triggers a monitoring alert. A board resolution, a named compliance officer with a CV cross-referenceable against the licensing application, and a defined escalation path from front-line compliance to senior management are the governance signals a bank-ready file should contain. A compliance structure that cannot be explained in two paragraphs will generate a queue of questions before the substantive review begins.

The role of the CBUAE guidance on VASPs

The CBUAE Guidance for Licensed Financial Institutions on Risks Related to VAs and VASPs is the operational document UAE banks use when evaluating VASP applications. It distinguishes between an administrative account (the VASP's own operating costs, no client money) and a transactional account (the VASP routes client funds through the bank). For a transactional account, the conditions include: the VASP is licensed, operates its own AML/CFT framework, has Travel Rule controls, and applies CDD to its own clients. The guidance also requires the bank to obtain a CBUAE non-objection before opening a transactional client-money account — a step that extends the timeline beyond the standard six-to-eight week band and that many founders discover only after submitting the application.

A VASP that acknowledges the non-objection requirement in its cover letter and includes the documentation that review requires shortens the process materially compared with one that reframes the application mid-review.

What a bank-ready file contains

A file that moves through the compliance-desk sequence without stalling looks roughly like this.

The entity section contains the constitutional documents, the ownership chart walked to natural persons, the licence with the permission type visible, and evidence that the licence is current. For a VARA-licensed VASP this means the active licence document and the VARA public register entry.

The compliance section contains the AML/CFT policy at the level of detail described above — not a generic template — the name and CV of the MLRO, the Travel Rule solution and provider name, and the wallet-screening policy.

The business description contains a summary of the products, the transaction flow by product type, the client categories, volume estimates by corridor, and the fee structure. It should match the website and the licence. Where the website does not currently match, update it before submitting the application.

The source-of-funds section contains the prior bank statements, share-subscription documents, investor confirmation, or converted-asset trail. For a VASP holding crypto as treasury, this means the fiat origin — not a screenshot of a wallet balance.

The covering letter summarises all of the above in one or two pages, acknowledges the VASP's licensing status, identifies the account type being requested (administrative or transactional), and pre-answers the questions the analyst would otherwise have to ask. Ksenia Babochkina, Commercial Director at Medici Expert, captures the underlying dynamic precisely: "Crypto companies don't get rejected by banks for being crypto companies. They get rejected for not being able to explain themselves clearly." A covering letter that explains the company clearly — products, permissions, compliance framework, and transaction expectations — removes the conditions under which that rejection usually happens.

The licensing and company formation work that precedes the bank application — entity type, jurisdiction, licensing route, corporate structure — is the foundation that makes the file coherent. Structural gaps at that stage do not resolve at the application stage.

What changes if the application has already been refused

A recorded refusal requires a different sequence before the next application. UAE banks screen incoming applications against internal lists of previously declined customers, and the CBUAE guidance for LFIs on CDD and record-keeping reinforces that obligation. A VASP that applies to three banks in sequence without fixing the gap that produced the first refusal will typically receive three refusals.

The practical step after a refusal is to obtain the reason in writing where the bank's product terms allow it. From 13 September 2026, Regulation C 2/2026 Article 4.52 requires UAE licensed banks to record rejected SME applications and the reasons. Once the gap is identified — a CDD gap, a substance question, a licence mismatch, a Travel Rule absence — the file can be corrected before the next application.

Building and maintaining the compliance framework that backs the bank application — the AML policy, the KYB procedure, the Travel Rule controls, the governance structure — is the work that converts a rejected file into a bankable one. The gap is almost never the sector. It is almost always the documentation.

For the wider landscape of which UAE institutions underwrite VA activity and under what conditions, crypto compliance in 2026 covers the control stack that banks assess when they score a VASP counterparty.

FAQ

Why do banks refuse accounts for crypto companies?

Refusals fall into two categories: CDD failures and appetite decisions. A CDD failure means the bank cannot complete the required customer identification and risk assessment — usually because of an incomplete ownership chain, a missing licence, a thin AML policy, or a business description that does not match the licence and website. An appetite decision means the bank completed its CDD but declined the sector regardless. Most refusals that founders receive are CDD failures, which means they are fixable. Appetite decisions require finding a different institution. Asking the relationship manager about sector appetite before preparing the full document pack saves time in the appetite-refusal scenario.

Does a VARA licence guarantee a bank account?

A VARA licence materially improves the risk profile, but it does not guarantee approval. It establishes that the licensing authority has reviewed the ownership structure, business plan, and AML framework. The bank still runs its own CDD, makes its own risk-appetite decision, and — for transactional VASP accounts — must obtain a CBUAE non-objection before opening the account. A VARA licence held by a company with a thin AML policy and an incomplete source-of-funds pack will not automatically pass bank review.

What is the Travel Rule and why do banks ask about it?

The Travel Rule requires VASPs to pass originator and beneficiary information along with a virtual-asset transfer above a prescribed threshold. In the UAE, the obligation flows from Cabinet Resolution 134/2025 Article 36 and the CBUAE Virtual Assets Travel Rule (In-Force, August 2026). Banks ask because it tells them whether the VASP can identify and screen the counterparties in its transaction flows. A VASP without a named Travel Rule solution and a documented counterparty-VASP verification procedure is one that cannot answer a basic question about its own transaction population — and that is a risk the bank has to price or decline.

How long does bank onboarding take for a VASP in the UAE?

Medici's public FAQ cites six to eight weeks for a high-risk crypto or fintech file, counted from a complete document pack. For a VASP applying for a transactional account, the CBUAE non-objection process adds to that clock, and the total timeline can exceed three months. Incomplete documents restart the count. Preparing the full file before the first submission — rather than completing it reactively as the bank requests missing items — is the most direct way to compress the timeline.

What AML documents does a VASP need for bank onboarding?

The minimum pack includes: an AML/CFT policy covering client CDD, transaction monitoring, sanctions screening, SAR procedure, and record-keeping; evidence of the Travel Rule solution and counterparty-VASP verification process; the name and CV of the MLRO; and the wallet-screening provider and rule set. Each document should reflect the VASP's actual operations. A generic policy that does not name the company's actual tools or client categories is unlikely to satisfy the bank's review. The specificity of the compliance documentation signals whether the company has built a compliance function or purchased a document.

Can a crypto company in the UAE use an EMI account instead of a bank account?

An EMI or payment institution account can cover some operational needs — multi-currency settlements, fiat rails for exchange flows — but it does not substitute for a UAE corporate bank account in all contexts. UAE payroll through the Wage Protection System requires a UAE-licensed bank account. Local supplier AED and government-fee payments typically require a UAE IBAN from a licensed bank. EMI accounts work well for international settlement, but a UAE-registered VASP usually needs at least one UAE-licensed bank account alongside any EMI rails. The right combination for a specific structure is worth clarifying before applications are submitted.

What happens after the account is open?

The bank's monitoring continues throughout the relationship. Cabinet Resolution 134/2025 Article 8 requires the institution to scrutinise transactions against the customer's expected-activity profile and to refresh CDD when circumstances change. A VASP that shifts product, adds new corridors, or changes client categories without informing the bank creates a monitoring mismatch that triggers queries and sometimes account review. Event-driven updates — a licence amendment, a change in the MLRO, a new jurisdiction — should reach the bank in the same week they reach the regulator.

Connect with our experts

Get full clarity on licensing, compliance and structuring before you spend time and budget on the wrong move.

Book a Free Call

Ready to build a structure that actually works?

Whether you are launching a fintech company, applying for a license, entering the UAE, issuing a token or preparing for regulatory review — we can help you choose the right path before costly mistakes happen.

Book a Free Call