What Makes a Business “High-Risk” for Banking?
“High-risk” is a banking classification, not a verdict on a business’s legitimacy. Visa’s Integrity Risk Programme registers roughly twelve to fourteen merchant category codes as high-integrity-risk in 2026, covering gambling, pharmaceuticals, crypto, forex, dating, and inbound telemarketing (MCC 5967).[1] The label reflects risk modelling: chargeback exposure, regulatory complexity, fraud patterns, reputational sensitivity, and the monitoring burden the institution must carry.
The five risk dimensions are interlocking. Chargeback potential measures dispute rates against scheme thresholds. Visa’s Acquirer Monitoring Programme (VAMP), which replaced VDMP and VFMP in 2025, sets the merchant Excessive threshold at 1.5% (150 basis points) from for the US, Canada, EU, and AP regions (2.2% in the CEMEA region), with acquirer thresholds at 0.50% Above Standard and 0.70% Excessive.[2]
Mastercard’s Excessive Chargeback Programme operates the same 1.5% ratio for ECM and a 3.0% ratio for HECM, with fines escalating to $100,000 per month from month 19 of continuous breach.[3] Operators in 2026 plan to the 1.5% line, not the legacy VDMP figures of 0.9% or 1.0% that still circulate online.
Regulatory complexity measures the layering of authorisations the institution has to assess and re-assess. A licensed CASP under MiCA, a CySEC-regulated CFD broker, a UKGC-licensed iGaming operator, and a VARA-authorised crypto exchange each present a different regulatory perimeter, and the institution carries the cost of staying current on every one of them. Fraud exposure is measured through TC40 reports for cards and equivalent operational fraud metrics for bank rails.
Reputational risk is governed at a senior management level using the Wolfsberg Group’s Financial Crime Principles, with the Wolfsberg CBDDQ v1.4 (April 2024) explicitly covering virtual currencies. Transaction-monitoring burden is the practical workload: rule-based monitoring plus behavioural analytics plus on-chain analytics for crypto plus sanctions screening across multiple lists, refreshed daily.
How banks classify internally tracks closely to scheme tiering. A common internal taxonomy runs Standard, Enhanced, Restricted, and Prohibited: Standard for low-risk SMEs; Enhanced for moderate risk under uplifted enhanced due diligence; Restricted for the high-risk verticals (gambling, adult, crypto, money service businesses, payment service providers) requiring senior approval, enhanced reserves, and continuous monitoring; and Prohibited for sanctioned jurisdictions, shell banks, and unlicensed money service businesses. The MCC code attached to a merchant’s card acceptance feeds directly into this tiering.
MCCs 7995 (gambling), 6211 (financial trading), 5912 (pharmacies), 5967 (inbound telemarketing), 7273 (dating and escort), and 6051 (quasi-cash and crypto on-ramps) sit inside Visa’s three VIRP tiers.[1]
The classification is structural. Even a fully compliant, well-capitalised operator triggers it if the activity is in a flagged sector. FATF’s October 2014 position, reaffirmed through the June 2025 revision of Recommendation 1, holds that wholesale termination of customer classes is not consistent with the FATF standards, and that termination should be a case-by-case decision after risk mitigation has been exhausted.[4]
In practice, the label is more punitive than the underlying risk often justifies, but it is the operating reality every applicant has to plan around. The institution is not making a moral judgement; it is pricing the cost of monitoring an applicant across its compliance, financial-crime, and operational risk functions.
Unlike a standard e-commerce business, a crypto exchange triggers multiple risk flags simultaneously: regulatory uncertainty across jurisdictions, cross-border counterparty complexity, and pseudonymous transaction counterparties on chain. A licensed gambling operator triggers chargeback-rate exposure and Mastercard SPME §9.4.2 registration. An adult-content platform triggers Mastercard SPME §9.4.1 registration with age-verification and takedown procedures, after the 2021 AN 5196. The aggregation of flags, not any one flag, is what reclassifies the relationship as high-risk and changes the pricing, the documentation requirements, and the reserve profile.
Who Needs a High-Risk Business Account?
High-risk banking is not a crypto-only conversation. Eleven verticals carry the classification in 2026: crypto exchanges and CASPs, OTC desks, licensed gambling and iGaming, forex and CFD broking, CBD and legal cannabis, adult entertainment, stablecoin issuance, prediction markets and event contracts, DeFi infrastructure and custodial wallets, travel and ticketing, and regulated pharmaceuticals and nutraceuticals. Which one applies, and why, determines whether the right placement target is a traditional bank, an EMI, a specialist acquirer, or a multi-provider structure.
| Business Type | Risk Classification | Why Banks Flag It | Typical Banking Outcome |
|---|---|---|---|
| Crypto exchanges and CASPs | Very high | MiCA Title V perimeter; 303 CASPs authorised EU-wide (322 EEA-wide) as of per the ESMA MiCA Register (Germany, France, and the Netherlands leading); Chainalysis 2026 report attributes USD 154bn to illicit addresses in 2025, of which 84% via stablecoins[5] | EU EMI safeguarding paired with credit-institution-tier custodian; traditional bank rare for new entrants |
| OTC desks | Very high | Large-ticket fiat flows, source-of-funds opacity, sanctioned-counterparty exposure | Specialist EU/UK EMI with crypto-permissive safeguarding plus correspondent in EU or APAC; offshore secondary |
| Gambling and iGaming operators (licensed) | High to very high | UKGC LCCP, MGA Player Protection Directive; chargeback exposure ~0.83% in licensed European iGaming;[6] Mastercard SPME §9.4.2; Visa VIRP Tier 1 | EMI plus specialist acquirer for UKGC/MGA; specialist acquirer plus offshore route with 10–20% rolling reserves held 180 days or more for Curaçao |
| Forex and CFD brokers | High to very high | ESMA leverage caps (30:1 majors, 2:1 crypto); 74–89% of retail accounts lose money; B-book conflict-of-interest exposure | EU credit institution feasible for established firms; otherwise EMI plus specialist FX acquirer; offshore arms route via offshore PSP plus crypto on/off-ramp |
| CBD and legal cannabis | Very high | November 2025 US Continuing Resolution §781 redefined hemp THC; SAFER Banking Act not yet enacted; NCIA estimate January 2026: >70% of cannabis businesses lack basic banking | US: specialist state and regional credit unions and community banks plus closed-loop card rails. EU: specialist EEA EMI archetype with nutraceutical or medical registration |
| Adult entertainment operators | Very high | Mastercard SPME §9.4.1 adult-content registration with age verification, written performer contracts, takedown procedures; 18 USC §2257; UK Online Safety Act 2023 age assurance | Specialist offshore acquirer paired with EU EMI safeguarding; non-card APMs and crypto increasingly used to reduce card exposure |
| Stablecoin issuers (post-MiCA) | High to very high | MiCA Titles III/IV apply since ; ≥60% reserves for significant EMTs in EU bank deposits across multiple institutions; Article 23 caps non-euro EMT use as means of payment at €200m/day | MiCA-authorised EMT issuers: EU credit-institution access through issuer entity. Non-authorised issuers: closed out of regulated EU venues by |
| Prediction markets and event contracts | Moderate-high to very high | DC Circuit October 2024 cleared political event contracts; state-AG actions through 2025–26 on sports contracts; 17 CFR §40.11 prohibitions remain | US CFTC-regulated DCMs: traditional US bank via FCM relationships. Offshore DEX-based markets: crypto-only rails |
| DeFi infrastructure and custodial wallets | Very high (custodial); out of MiCA scope if fully decentralised | ESMA/EBA Joint Report under MiCA Article 142 (January 2025); MiCA Recital 22 exempts fully decentralised; custodial wallets fall within Article 3(1)(17) custody and need CASP authorisation | Custodial wallet operators and DeFi front-ends: EU EMI plus specialist correspondent. Pure protocol developers: EU credit institution access feasible as technology vendors |
| Travel and ticketing | Moderate-high to high | Long booking-to-delivery gap; insolvency cascades; Section 75 UK and chargeback rights drive ~78% consumer-win rate on travel disputes; highest average chargeback value at USD 120 in the 2025 Mastercard State of Chargebacks data | Traditional bank acquiring with 5–10% rolling reserves and deferred settlement; OTAs increasingly use virtual-card BIN-sponsored PayIn/PayOut |
| Pharmaceuticals and nutraceuticals | High to very high | Mastercard SPME §9.4.3 pharma and tobacco registration; Visa VIRP Tier 1 (unapproved pharma) or Tier 2 (supplements); subscription and continuity-billing chargebacks | Licensed online pharmacies: specialist healthcare acquirer. Nutra subscriptions: EU EMI plus specialist acquirer with 5–10% reserves and multi-MID structures |
Each vertical has its own banking ecosystem. Operators building crypto exchanges, stablecoin issuance, gambling, or regulated forex find that the right placement target shifts with the licence held: see crypto exchanges, stablecoin issuers, gambling licensing, and forex licensing for the licence-side path that pairs with this banking outlook.
Banking Options for High-Risk Businesses
The EMI account is the primary route: in practice, a crypto business bank account usually means an EMI account. A traditional bank account is achievable, but effectively only with a regulatory licence already in place. Offshore banking fits offshore-incorporated holding entities and non-EU operating companies where EU or UK IBAN issuance is not commercially material. A multi-provider structure layers two or three of those so that no single sponsor chain can stop the business.
Traditional Bank Accounts
Traditional bank accounts are achievable for high-risk operators where the institution can underwrite the regulatory perimeter. Three archetypes carry the market in 2026:
- FINMA-supervised digital-asset banks in Switzerland. Typical operating balance CHF 1m–3m, onboarding 8–16 weeks.
- BaFin-licensed German commercial banks holding crypto custody permission under KWG §1(1a) sentence 2 no. 6. Operating balance €500k–€2m, onboarding 6–14 weeks.
- UAE banks with VARA, ADGM, or DFSA-aligned VASP desks. Operating balance AED 250k–1m, onboarding 6–14 weeks; the Central Bank of the UAE granted its first VASP Stored Value Facility licence on .
Traditional banks accept MiCA-authorised CASPs more readily than unregulated entities and apply higher minimum-relationship size thresholds than EMIs. Experienced applicants budget the operating-balance floor as a structural prerequisite rather than a negotiable opening: the same CHF 1m–3m or €500k–€2m that funds onboarding is what unlocks the relationship terms (FX margins, SWIFT routing, custody-pricing waivers) that make the account commercially viable.
EMI Accounts
Unlike retail banks, which apply a single risk appetite across the institution, an EMI’s appetite is calibrated to high-risk verticals from the outset rather than retrofitted to accommodate them. The operational consequence is faster onboarding, lighter relationship-size thresholds, and a documentation process built for crypto and fintech profiles rather than against them.
EMI accounts are the primary route for most high-risk operators. The legal basis is Directive 2009/110/EC (EMD2), which created a regulated category specifically to extend payment access to sectors that retail banks underserved.[8] EMIs provide SEPA Credit Transfer, SEPA Instant, indirect SWIFT correspondent access, and multi-currency IBANs under EEA passporting.
They cannot accept deposits, cannot pay interest, and are not covered by deposit-guarantee schemes such as the FSCS (£120,000 per claimant from ) or the EU DGSD (€100,000).
Instead, EMIs safeguard client funds in segregated accounts at credit institutions under EMD2 Article 7. Typical onboarding for high-risk verticals runs 4–10 weeks (versus 2–6 weeks for low-risk B2B).
UK-supervised EMIs are now subject to the FCA’s Supplementary Safeguarding Regime under Policy Statement PS25/12, in force from , which requires daily reconciliation of safeguarded balances, a monthly safeguarding return to the FCA, and an annual safeguarding audit by a qualified independent auditor.[9]
Operators choosing an EMI in 2026 should verify the firm has implemented the PS25/12 regime across all four required functions (daily reconciliation, monthly return, annual audit, governance attestation); an EMI still operating under pre-May 2026 reconciliation cadence is a material counterparty risk.
Offshore Banking
Offshore banking is appropriate for offshore-incorporated holding entities, non-EU operating companies, and structures where EU or UK IBAN issuance is not commercially material. As of the FATF plenary of , the Cayman Islands remains off the FATF grey list (delisted November 2023) and off the EU AML high-risk list, while the British Virgin Islands was added to the FATF grey list on and to the EU AML high-risk list under Delegated Regulations (EU) 2026/46 and 2026/83, effective ; AIFMD 2.0 prohibits marketing of investment funds from EU-AML-listed jurisdictions under private placement regimes from .
Mauritius, which is classed midshore rather than strictly offshore, retains the strongest correspondent banking in this group. Local banks nonetheless decline pooled end-client fiat for trading models in most cases, so elevated-risk profiles keep client-facing flows on EU or UK payment-institution rails. The constraint to plan around is IBAN acceptance: an offshore-domiciled entity holding only a non-EEA IBAN does not benefit from Article 9 of Regulation (EU) 260/2012 (SEPA Regulation), and counterparties may lawfully refuse the payment.[10]
Multi-Provider Strategy
Multi-provider banking is the prudent default for any crypto, fintech, or high-risk operator processing more than €1m annually. Single-provider dependency is no longer a tolerable risk profile, given the 2024 banking-as-a-service middleware collapse, the FCA’s findings on EMI safeguarding shortfalls (the regulator’s pre-PS25/12 dataset identified average shortfalls of 65% between funds owed and funds safeguarded across twelve insolvent payment firms, with a 2.3-year average to first distribution), and the cascading 2023–2025 OCC, FDIC, and Federal Reserve consent orders against US sponsor banks supporting BaaS programmes.[7][9]
The recommended structure is a primary EEA-passported EMI for SEPA and multi-currency IBANs, a secondary EMI or licensed institution in a different jurisdiction and sponsor chain, and a traditional bank where the business profile permits, for treasury, large-value SWIFT, and credit access.
We also coordinate crypto-to-fiat settlement and on-chain stablecoin rails alongside the fiat structure. Operators who rely on one EMI for SEPA and one acquirer for cards are one consent order or one middleware insolvency away from a full operational stop.
Documentation and Compliance Requirements
Documentation for high-risk banking is materially more demanding than standard know-your-business. Three categories matter: the universal corporate package, the high-risk-specific overlay that every applicant in a flagged sector has to deliver, and the ongoing monitoring obligations the institution applies after the account opens. Incomplete documentation is the single most common cause of application stalls.
In practice, the documentation gap that stalls applications is rarely a missing item; it is an inconsistent narrative across the cap table, AML policy, fund-flow diagram, and source-of-wealth file, where one document implies a structure the others do not corroborate.
Standard KYB Documentation
The universal package required across all high-risk applications follows the EU AMLR (Regulation (EU) 2024/1624) Article 22 framework and FATF Recommendations 24 and 25 on beneficial ownership.[11][12] It covers:
- certificate of incorporation
- articles or memorandum
- current share register and cap table with all ultimate beneficial owners at the 25% threshold (15% for high-risk sectors at Commission discretion)
- certificate of good standing or incumbency
- register of directors with fit-and-proper evidence
- the most recent two years of audited financial statements
- three-year financial projections
- a fund-flow diagram
- a written business plan
- and proof of operating address
The package should be a single indexed bundle, not assembled ad hoc as the institution requests items. The US Corporate Transparency Act position changed on : FinCEN’s Interim Final Rule exempts US-formed entities and US persons from BOI reporting; only foreign reporting companies must file.
High-Risk-Specific Documentation
The overlay specific to high-risk verticals is where most applications fail. A bespoke AML/CFT policy manual is mandatory; template manuals lifted from another operator’s licensing pack are the single most common reason an application loses momentum at week six. The FCA’s January 2024 Zeux Limited decision refused MLR registration specifically for inadequate business-wide risk assessment, and that decision now sets the bar institutions apply.[13]
EBA Guidelines EBA/GL/2024/01 (applicable to CASPs from ) require methodology, sources used, control-effectiveness testing, and a linear mapping of inherent risks to controls to residual risks.[14]
For crypto operators, the high-risk documentation pack adds:
- Blockchain analytics contract: an executed contract rather than a trial account, covering every chain the business settles on.
- Wallet disclosure: covering all operational addresses.
- Custody operating model: hot/warm/cold split, MPC or multisig, key-ceremony procedures, custodian counterparties.
- Source-of-wealth and source-of-funds evidence trail: traceable through fiat to crypto to gains to fiat.
- Security certifications: increasingly expected at SOC 2 Type II, ISO/IEC 27001:2022, and PCI DSS v4.0.1 where card data is processed.
- Proof of the regulatory licence held: MiCA CASP authorisation, FCA cryptoasset registration, FINMA supervision, VARA/ADGM/DFSA authorisation, or MAS DPT/DTSP licence.
What Banks Check During Ongoing Monitoring
Ongoing monitoring is governed by Article 26 of the EU AMLR, applicable from , and by the existing EBA Guidelines EBA/GL/2021/02 as amended by EBA/GL/2023/03, EBA/GL/2023/04, and EBA/GL/2024/01.[11][14] The new EU Anti-Money Laundering Authority (AMLA) has been operational since , with headquarters at the Messeturm in Frankfurt; AMLA assumed all EBA AML/CFT mandates on and begins direct supervision of approximately 40 selected obliged entities (including cross-border CASPs) on .[15]
Typical post-onboarding cadence runs quarterly compliance reviews, behavioural transaction monitoring, daily sanctions re-screening, a documented suspicious activity report pipeline, annual wallet re-disclosure with event-driven updates, and enhanced due diligence refreshes (annual for high-risk, every two years for medium-high, every three years for medium). New York Banking Organisations now apply equivalent expectations under NYDFS’s Industry Letter extending blockchain-analytics requirements to all chartered institutions and foreign-branch operations.[16]
The honest editorial position is that documentation discipline matters more than licence prestige for most operators at the placement stage. An MGA-licensed gambling operator with a polished, business-specific compliance pack and a clean Mastercard SPME §9.4.2 registration record will out-place a UKGC-licensed operator submitting template policies and a stale audit. Licence type is what gets a profile considered; documentation discipline is what gets it accepted.
What High-Risk Banking Costs
The multiple holds across the whole stack: monthly maintenance, SEPA, SWIFT, FX, and card processing. It prices the compliance and monitoring burden the institution has to carry, not a penalty levied against the individual business. The 2026 ranges follow, with the rolling-reserve mechanic that distorts cash flow worked through in cash terms.
The real constraint for most high-risk operators is not the headline transaction fee but the rolling reserve: a 10 percent reserve on card-processing volume of €5m monthly withholds €500k each month and locks €3m continuously once the 180-day window has filled, and operators routinely undercapitalise this line on the cost projection.
| Fee Type | Medium-Risk Fintech | High-Risk (Gambling, Forex, CBD) | Very-High-Risk |
|---|---|---|---|
| Monthly maintenance | €25–€75 | €50–€500 | €500–€1,000+ |
| Setup or application review | €200–€500 | €450–€1,500 | €2,000–€10,000+ |
| SEPA outgoing per transaction | €0.50–€2.00 | 0.04–0.10% with €2–€7 minimum (cap €200), or flat €3–€10 | €5–€15 flat; some tariffs ad valorem with no cap |
| SWIFT outgoing | 0.1–0.2% + €7–€25, SHA/OUR | 0.2–0.5% + €15–€25 | OUR-only routing, €40–€100 + correspondent fees |
| FX spread over interbank mid | 0.5–1.0% | 1.0–2.0% | 2.0–3.5%+ |
| Rolling reserve % | 0–5% | 5–10% | 10–20% |
| Reserve hold period | 60–90 days | 90–180 days | 180–365 days |
| Card processing (effective MDR) | 2.5–3.5% | Licensed gambling 3.5–8%; CBD 3.95–8%; forex 4–8% | Adult 5–10% (extreme 7–16%) |
Unlike standard SME pricing, which is set by the institution’s published tariff and rarely negotiated, high-risk banking pricing is bilateral, dynamic, and moves down with three levers. A regulatory licence in place at the application stage (MiCA CASP, FCA cryptoasset registration, FINMA, BaFin, VARA, MGA, UKGC) compresses the friction premium toward the medium-risk tier.
Transaction-volume commitments above €100,000 monthly secure 0.2–0.5% markup reductions, with tiered rebates at €500k, €1m, and €5m thresholds. The most consistent lever is compliance infrastructure maturity: SOC 2 Type II, ISO 27001:2022, a dedicated MLRO, Travel Rule readiness, and a documented chargeback workflow holding dispute rates under 0.5% all reduce the effective rate. Reserve negotiations rarely succeed in the first quarter; they open up after the third or fourth month of clean processing data, and step down from 15% to 10% to 7.5% over an 18-month horizon.
How Jagelski & Partners Helps
Jagelski & Partners pre-qualifies high-risk businesses across 90+ banking and payment institutions, identifying the providers most likely to accept an application before it is formally filed. The partner network maintains live account-opening routes in every jurisdiction Jagelski & Partners services, and banking feasibility is confirmed at the scoping stage, before any licence application is filed.
Through Jagelski & Partners’ partner network, businesses placed more than fourteen billion euros in client turnover across banking and EMI relationships in 2025. Each business is pre-qualified across the network before any formal application, and the institutional rate is passed through without markup. There is no onboarding fee.
Pre-qualification process. Pre-qualification is a 3–5 business-day exercise in which we present an anonymised business profile against the current acceptance criteria of institutions across the network. The institutions confirm appetite (yes, qualified yes, or no) before any application is submitted. The client does not formally apply to any institution until the placement is matched, which removes the rejection-history risk that comes from going door-to-door.
Multi-provider strategy. The placement is not a single account. The recommended structure for any high-risk operator processing material volume is a primary EEA-passported EMI, a secondary EMI or licensed institution in a different jurisdiction and sponsor chain, and a traditional bank where the business profile permits.
We coordinate onboarding across all three so that operational dependency is split from day one. Jagelski & Partners is paid by the institution, not by the client. The placement carries no onboarding fee. Institutional banking and EMI pricing is passed through without markup.
Ongoing relationship. After account opening, we remain the channel between the client and the institution. We support EDD refreshes, sanctions queries, transaction-monitoring alerts, and the periodic re-disclosure cycles the institution requires. The placement does not end at account activation; it runs for the life of the relationship.
What the service does not do. Jagelski & Partners does not guarantee account opening. Pre-qualification identifies institutions most likely to accept the profile; it does not commit those institutions to approval. We do not pursue placement for businesses whose model the network cannot underwrite.
Frequently Asked Questions
“High-risk” is a banking and card-scheme classification applied to industries whose risk profile (chargeback exposure, regulatory complexity, fraud patterns, reputational sensitivity, or transaction-monitoring burden) exceeds the institution’s standard tolerance. Visa registers roughly twelve to fourteen merchant category codes as high-integrity-risk under its 2026 Integrity Risk Programme, including gambling, pharmaceuticals, crypto, forex, dating, and inbound telemarketing (MCC 5967). The label reflects risk modelling, not a judgement on the business’s legitimacy.
Even fully compliant operators in flagged sectors are classified high-risk because the classification attaches to the structure of the activity, not the operator.
Yes, in specific jurisdictions and with specific business profiles. FINMA-supervised digital-asset banks in Switzerland, BaFin-licensed German commercial banks with crypto custody permission under KWG §1(1a) sentence 2 no. 6, and UAE banks with VARA, ADGM, or DFSA-aligned VASP desks all open accounts for qualifying high-risk operators in 2026.
Acceptance depends on licence status, transaction profile, jurisdictional fit, and minimum relationship size (typically CHF 1m–3m, €500k–€2m, or AED 250k–1m). Onboarding takes 6–16 weeks. MiCA-authorised CASPs report measurably better access to traditional banks than unregulated entities.
Monthly maintenance for high-risk EMI accounts runs €50–€500, with setup fees of €450–€1,500. SEPA outgoing fees are typically €3–€10 flat or 0.04–0.10% ad valorem with a €2–€7 minimum (capped around €200). SWIFT outgoing fees run 0.2–0.5% plus €15–€25. FX spreads run 1.0–2.0% over interbank mid.
Card processing for licensed gambling runs 3.5–8%, CBD 3.95–8%, forex 4–8%, and adult 5–16%. Rolling reserves of 5–10% are held 90–180 days. The overall premium versus standard SME banking runs 5–15× across the cost stack.
A rolling reserve is a percentage of processed card volume withheld by the acquirer as a chargeback buffer. Typical ranges in 2026 are 0–5% for medium-risk fintech held 60–90 days, 5–10% for high-risk businesses held 90–180 days, and 10–20% for very-high-risk tiers held 180–365 days. The steady-state impact: a merchant processing €100,000 monthly at a 10% reserve over 180 days locks €60,000 of cash continuously from month six.
At euro-area SME funding costs of 6–8% per annum, that float carries €3,600–€4,800 in annual financing cost on top of processing fees.
Three layers. The universal corporate package covers certificate of incorporation, articles, share register with UBO disclosure at the 25% threshold (or 15% for high-risk sectors), audited financial statements, three-year projections, business plan, and fund-flow diagram. The high-risk-specific overlay covers a bespoke (not template) AML/CFT policy manual, blockchain analytics contract for crypto operators, wallet disclosure, custody operating model, source-of-wealth evidence trail, security certifications (SOC 2 Type II, ISO 27001:2022, PCI DSS v4.0.1 where applicable), and proof of regulatory licence. Ongoing monitoring then runs quarterly compliance reviews, daily sanctions re-screening, and EDD refreshes annually.
EMI account onboarding for high-risk verticals typically takes 4–10 weeks (versus 2–6 weeks for low-risk B2B). Traditional bank onboarding takes 6–16 weeks depending on jurisdiction: FINMA-supervised digital-asset banks 8–16 weeks; BaFin-licensed German banks 6–14 weeks; UAE banks with VARA or ADGM desks 6–14 weeks.
Jagelski & Partners’ pre-qualification stage takes 3–5 business days and identifies the institutions most likely to accept the application before any formal submission, materially reducing the risk of entering a long onboarding process at an institution that will ultimately decline.
Yes, materially. MiCA-authorised CASPs report significantly better banking access than unregulated entities. The UK FCA cryptoasset register, FINMA supervision, BaFin authorisation, and VARA, ADGM, or DFSA authorisation each function as a banking credential. Licensed gambling operators under UKGC, MGA, IOM, or Gibraltar regimes face lower friction than offshore-licensed equivalents. The licence does not guarantee banking access (75% of crypto hedge funds still reported difficulties in the AIMA December 2024 survey), but it is effectively a precondition for tier-1 institutional banking in most jurisdictions. See Crypto & Fintech Licensing for the licence-side path.
A high-risk bank account holds operating funds, receives SEPA and SWIFT transfers, issues outbound payments, and provides multi-currency IBANs. A high-risk merchant account processes card payments (Visa, Mastercard, sometimes Amex) and settles the net into a bank account. The two are distinct products with separate underwriting, separate compliance requirements, and separate fee structures.
Most high-risk operators need both. A merchant account does not function as a bank account; an EMI bank account does not process cards unless paired with an acquirer relationship. Pre-qualified placement coordinates both so that operating and processing rails come online together.
Jagelski & Partners is paid by the institution that takes the client’s business, in the form of a referral or revenue-share arrangement. The institution extends this arrangement because the network delivers volume (through Jagelski & Partners’ partner network, businesses placed more than fourteen billion euros in client turnover across banking and EMI relationships in 2025) and because the introductions are pre-qualified, which materially reduces the institution’s onboarding cost. The pricing the client sees on their account-opening documentation is the institutional rate. There is no markup. There is no onboarding fee billed to the client.
No. Jagelski & Partners does not charge a banking onboarding fee. Compensation comes from the institution’s referral or revenue-share arrangement, not a fee billed to the client. Neither the banking placement nor the advisory, regulatory or document work around it carries a fee payable by the client; the partner pays us for the introduction.
Ready to Place Your High-Risk Business with Banks That Will Underwrite You?
Book a banking assessment. The process pre-qualifies the business across 90+ banking and EMI institutions, presents a shortlist of providers most likely to accept the application, and coordinates onboarding through to account activation. No markup on institutional pricing. No onboarding fee. The assessment itself takes 3–5 business days.
References
Show all references
- Visa Inc., Visa Merchant Data Standards Manual (integrity-risk MCC provisions) (April 2026 edition), corporate.visa.com, accessed .
- Visa Inc., Visa Acquirer Monitoring Programme (VAMP) Fact Sheet (2025); Acquirer Above Standard 0.50% / Excessive 0.70%; merchant Excessive 150 bps from , corporate.visa.com, accessed .
- Mastercard Inc., Mastercard Security Rules and Procedures (Edition 2025), Excessive Chargeback Programme (ECM/HECM) and Excessive Fraud Merchant Programme (EFM), accessed .
- Financial Action Task Force, FATF Public Statement on De-risking (October 2014, reaffirmed June 2025 revision of Recommendation 1), fatf-gafi.org, accessed .
- Chainalysis, 2026 Crypto Crime Report (January 2026), chainalysis.com 2026 Crypto Crime Report, accessed .
- European Gaming and Betting Association, Data on licensed iGaming card chargeback rates (2025), accessed .
- United States Bankruptcy Court, Central District of California, In re Synapse Financial Technologies, Inc., Case 1:24-bk-10646-MB (filed ; Chapter 11 case dismissed ); November 2024 court filings record peak-platform metrics of approximately 120 fintech customers and 2 million active users; Consumer Financial Protection Bureau adversary proceeding and stipulated final judgment (), accessed .
- European Union, Directive 2009/110/EC on the taking up, pursuit, and prudential supervision of the business of electronic money institutions (EMD2), Article 7 on safeguarding requirements, eur-lex.europa.eu, accessed .
- Financial Conduct Authority, Policy Statement PS25/12: Changes to the Safeguarding Regime for Payments and E-Money Firms (; Supplementary Regime in force ; PS25/12 §2.3 retains the average 65% safeguarding-shortfall figure across 12 insolvent payment firms from the antecedent CP24/20 dataset), fca.org.uk PS25/12, accessed .
- European Union, Regulation (EU) No 260/2012 (SEPA Regulation), Article 9 (IBAN discrimination), eur-lex.europa.eu, accessed .
- European Union, Regulation (EU) 2024/1624 (Anti-Money Laundering Regulation, AMLR), Articles 22, 25, 26, 27 (applicable from ), eur-lex.europa.eu, accessed .
- Financial Action Task Force, Recommendations 24 and 25 on Transparency and Beneficial Ownership (revised March 2022 and February 2023), fatf-gafi.org, accessed .
- Financial Conduct Authority, Decision Notice: Zeux Limited (January 2024), fca.org.uk, accessed .
- European Banking Authority, Guidelines EBA/GL/2024/01 amending EBA/GL/2021/02 on customer due diligence and ML/TF risk factors, including for crypto-asset service providers (applicable from ), eba.europa.eu, accessed .
- European Anti-Money Laundering Authority (AMLA), Official communications (operational since ; direct supervision from ), amla.europa.eu, accessed .
- New York State Department of Financial Services, Industry Letter: Notice on Use of Blockchain Analytics by NY Banking Organisations (), dfs.ny.gov, accessed .