Short answer

Sometimes, but the licence is not what decides it. Authorisation moves you out of the category banks treat as highest-risk; the account itself is still a commercial decision each bank makes alone, and it can be withdrawn later at the bank’s discretion.

There is a sentence founders hear a lot and should stop believing: get the licence and the banking follows. It does not follow. A licence and a bank account are decided by two different institutions, against two different tests, at two different moments — and only one of those institutions has any duty to explain itself to you.

Is your bank your regulator?

No, and the distinction matters more than any other point in this article. Your regulator authorised you against a published rulebook, and if it refuses you it must generally tell you why. A bank is a private counterparty deciding whether to take on a risk it will have to defend to its own supervisor, its own financial-crime committee and, in some cases, its own correspondent banks. It owes you no rulebook and, in most jurisdictions, no reasons.

What supervisors have done is narrow the space in which banks may refuse categorically. They have not created a right to an account, and no supervisor has said they intend to.

What did MiCA actually change for banks?

It changed the question a bank asks about you. In its final amending guidelines of 16 January 2024 (EBA/GL/2024/01), the European Banking Authority told banks that they may be exposed to increased risk where they enter business relationships with providers of crypto-asset services that are not regulated and supervised under Regulation (EU) 2023/1114 — MiCA (EBA/GL/2024/01, final report).

Read that as a bank would. It does not instruct anyone to onboard authorised firms. It tells a bank that the unauthorised firm is the one carrying the surcharge. The practical effect for an authorised business is that the conversation starts from a different place — not that it ends well. The MiCA transitional period closed on 1 July 2026, so within the EU the population of firms is now cleanly split into those with CASP authorisation and those that cannot lawfully serve EU clients at all. Banks can see that line, and they use it.

Why banks refuse in the first place

The EBA gave the behaviour a name and a definition. In EBA/GL/2023/04, published 31 March 2023, de-risking is defined as “a refusal to enter into or a decision to terminate business relationships with individual customers or categories of customers associated with higher ML/TF risk, or to refuse to carry out higher ML/TF risk transactions” (EBA/GL/2023/04).

Those same guidelines tell institutions that their policies should not result in “the blanket refusal or termination of business relationships with entire categories of customers” assessed as higher risk. But read the next paragraph, which is the one that gets skipped: institutions are expected to set out in their policies the criteria on which they will decide that a business relationship may be rejected or terminated. The supervisor is not removing the exit. It is asking the bank to write the exit down.

There is a second, quieter reason that has nothing to do with your file. The Basel Committee on Banking Supervision published its standard on the prudential treatment of cryptoasset exposures on 16 December 2022, adding a framework chapter (SCO60) covering banks’ exposures to cryptoassets including tokenised traditional assets, stablecoins and unbacked cryptoassets (BCBS, Prudential treatment of cryptoasset exposures). Where holding or facing the sector costs a bank capital and supervisory attention, a small account has to justify a fixed cost. Plenty of good applications fail on that arithmetic alone, and no amount of documentation fixes it.

What the bank is actually underwriting

An account application is read by several people who want different things. Being ready means having an answer that survives all of them, not just the relationship manager who was friendly on the call.

Who reads your fileWhat they are trying to establishWhat satisfies them
Relationship / commercialIs this account worth the servicing cost?Realistic volumes, a named operating entity, a reason this bank rather than any bank
KYC / onboardingCan every owner and controller be identified to a natural person?An ownership chart to the top, official register entries, consistent names across documents
Financial crime / AMLWhere does the money come from and where does it go?Source of funds and source of wealth with traceable evidence; counterparty and flow-of-funds mapping
SanctionsAny exposure to restricted persons, chains or jurisdictions?Screening tooling named, geographic exclusions stated and enforced in the product
Transaction monitoringCan we set thresholds that will not alert every week?Expected transaction count, value bands, currencies and seasonality — stated in numbers you will hold to
Credit / prudentialWhat does carrying this relationship cost us?Nothing you control; this is where small accounts quietly die

The account you get is not always the account you asked for

Treating “bank account” as one thing is a common planning error. In practice a licensed business usually ends up with a ladder, and the rungs fail independently:

Because the rungs fail independently, running a single banking relationship is itself an unhedged exposure. Firms that survive an account closure are almost always the ones that had opened a second relationship before they needed it.

Why accounts close after they open

The definition above covers termination as well as refusal, and termination is where most damage is done, because by then payroll runs through the account. In practice the trigger is rarely one suspicious payment. It is drift: the declared model and the observed model stop matching. Volumes an order of magnitude above the application. Counterparties in a region the file said was excluded. Retail-shaped inflows in a business that described itself as institutional. A bank does not litigate each item — it concludes that the original representation was unreliable, and that conclusion is very hard to argue back.

The discipline is unglamorous: tell the bank when the model changes, before the data does. An annual review that confirms what you already reported is a different meeting from one that discovers it.

A workable sequence

  1. Build the banking file during the licence application, not after it. The evidence overlaps heavily, and doing it twice tends to produce two versions of the truth — which is the one thing you cannot afford.
  2. Make everything independently checkable. Where a public register can confirm a fact, cite the register rather than supplying your own document. This is the same standard we hold ourselves to on our entity proof page.
  3. Quantify the model. “Low volume, institutional clients” is not a monitoring parameter; a stated range is.
  4. Open the second relationship while the first one is healthy.
  5. Keep the compliance officer real, reachable and briefed. A bank that cannot get a straight answer from your named officer will draw its own conclusion.

Where CryptoLicense fits

Bank and financial-institution account opening is one of our service lines, covering the UK, the EU and Singapore, alongside card issuing in Singapore and Hong Kong. The approach is to build the evidence once, at licensing stage, in the shape a bank’s financial-crime function reads it — rather than reconstructing it under time pressure after authorisation. See banking and card issuing and life after the licence.

What cannot be promised: no adviser can secure a bank account. Banks accept, refuse and close accounts at their own discretion, and regulators retain full discretion over authorisation. CryptoLicense is an advisory firm — not a regulator and not a law firm — and nothing here is legal advice. What can be committed to is the quality of the file and the consistency between what you say and what your account will show.

本文属于系列指南:完整指南见 牌照之后:银行开户、发卡与现货牌照.