Banking & Payments

Getting a SEPA IBAN for a high-risk business: the realistic playbook

If you run a crypto platform, payment business, gambling operation, affiliate network, FX desk, or anything else that makes compliance teams twitch, getting a SEPA IBAN can feel weirdly harder than building the actual business.

And honestly, that’s often true.

Founders usually start with the wrong assumption. “We’re incorporated in Europe, so a bank account should be simple.” Nope. Banks and EMIs don’t really care that your company registry extract looks neat. They care whether your activity, flows, counterparties, customer base, source of funds, and compliance controls fit their risk appetite. That’s the real test.

This is where plenty of applications die. Not because the business is illegal. Because it looks messy, rushed, under-explained, or structurally confused.


First, be clear on what you’re actually asking for

A SEPA IBAN isn’t one thing.

You might be applying for:

  • a standard corporate current account with a bank
  • an EMI account with named IBAN capability
  • a collections account for client payments
  • a safeguarding-related setup if you’re in regulated payments
  • an operational account for treasury, payroll, supplier spend, and tax

Those are very different asks. And they get reviewed differently.

If you’re a crypto brokerage wanting euro rails for customer deposits, that’s not the same as a B2B SaaS company that happens to accept stablecoin from a few clients. Same word – “crypto” – very different risk read. Gambling is the same story. A white-label B2B game provider with licensed counterparties is not the same as a direct-to-player casino targeting half the planet.

So before you send a single application, define the use case with painful clarity. Incoming payments from whom. Outgoing payments to whom. Average ticket size. Monthly volume. Countries. Expected peaks. Refund profile. Chargeback exposure. Whether client money is involved. If you can’t explain the flow in two minutes, the relationship manager won’t be able to defend you internally. Big problem.


The biggest mistake: applying before the structure is ready

I’ve seen founders apply for a SEPA IBAN with a fresh company, no real website, placeholder policies, a generic pitch deck, and a shareholder chain that takes three diagrams to explain. Then they’re shocked by the rejection.

From the bank’s side, it looks like this: unclear business model, unclear beneficial ownership, unclear compliance maturity. Easy no.

You need the structure to make sense before the banking outreach starts. That includes the company itself, the ownership chain, the operational geography, and the licensing position.

Sometimes the answer is setting up the right vehicle first. Not the cheapest vehicle. The right one. If your customers are in the EEA and you need euro settlement, using an offshore holdco as the trading entity and then acting surprised that EU banking is hard… well, that’s self-inflicted. If you’re still deciding where the operating company should sit, sort that out first through company formation in multiple jurisdictions. A clean setup saves alot of pain later.

And if you’re a crypto business, don’t try to “bank first, figure out regulation later.” Banks have heard that song before. If your model points toward VASP registration, FCA crypto registration, or future MiCA alignment, show the plan early. This is exactly why founders look at VASP registration and MiCA compliance before they go heavy on payment rails.


What the bank or EMI is actually checking

Not just your passport and incorporation docs. That’s the easy bit.

They’re trying to answer three quiet questions:

  1. Do we understand what this business really does?
  2. Can this client control AML, fraud, sanctions, and chargeback risk?
  3. If something goes wrong, will we regret onboarding them?

That’s why you’ll get requests that feel repetitive. Source of wealth for UBOs. Customer journey screenshots. Processing history. Contracts with key counterparties. Licensing explanation. AML policy. Sanctions controls. Risk assessment. Sometimes a compliance questionnaire that runs 30 or 40 questions deep.

Annoying? Sure. Normal? Also yes.

The mistake is treating this like admin. It’s not admin. It’s sales, but for risk. You’re building a case that your business is understandable and controllable.


Your banking pack should answer questions before they’re asked

A decent application pack can move things along fast. A bad one creates endless back-and-forth until someone in onboarding gets tired and bins the file.

At minimum, prepare these properly:

  • group structure chart with UBOs, percentages, and countries
  • short plain-English business description – no buzzword soup
  • website, product demo, or platform screenshots that match the description
  • transaction flow map showing where funds come from and where they go
  • jurisdiction list for customers, suppliers, and counterparties
  • AML and sanctions summary tailored to your actual model
  • licensing or regulatory position memo, if relevant
  • proof of trading history or projected volumes with some logic behind them

That transaction flow map matters more than founders think. If you’re a gambling merchant, show player deposit route, PSP layer, merchant entity, payout logic, and supplier payments. If you’re a crypto OTC desk, show fiat in, asset execution, custody path, and fiat out. Keep it visual. Keep it simple.

And please make your risk scoring make sense. If your AML policy says every customer is “medium risk” unless they’re sanctioned, no bank is going to take that seriously. This piece on customer risk scoring is worth reading because banks absolutely do ask how your model works in practice.


Jurisdiction matters. But not in the lazy way people think

Founders love asking, “Which country is easiest for a SEPA IBAN?” Usually the wrong question.

There isn’t a magic jurisdiction where high-risk banking becomes easy. There are only better fits between your business profile and the institution reviewing it. Lithuania may work for one regulated fintech and be a dead end for an unlicensed crypto marketing funnel. A Czech or Estonian company might be fine for one B2B model and awkward for another. A UK company can still make sense in some structures, but if you need EEA payment rails, you need to think about the full operating picture, not just incorporation prestige.

If you’re comparing entity options as a non-resident founder, this breakdown of UK Ltd vs Estonian OÜ is a good place to start. Not because one always wins. Because the banking angle changes the answer.

And yes, substance helps. Real management. Real operational logic. Real counterparties. Not fake office nonsense. Banks can smell cardboard setups a mile away.


Don’t shotgun applications everywhere

I get why founders do it. You’re frustrated, timelines are tight, payroll is coming, and every provider says no or ghosts you. So you apply to fifteen institutions at once.

Usually a mistake.

Why? Because inconsistent answers spread fast, support teams compare notes more than people think, and rushed forms create contradictions. One application says you’re B2B only. Another says retail. One says expected monthly volume is EUR 200k. Another says EUR 2m. One says no exposure to high-risk jurisdictions. Another mentions merchants in LatAm and Africa. That’s enough to spook onboarding.

Better approach:

Start with a shortlist built around your exact use case, then tailor each application. A gambling affiliate business needs a different target list from a MiCA-track crypto exchange or an EMI with safeguarding needs. Fewer applications. Better quality. Higher hit rate.


What to do if you’ve already been rejected

First, don’t panic. One rejection doesn’t kill the process. Five badly handled ones might.

Ask yourself what the rejection really means. Sometimes it’s policy. They simply don’t onboard your sector. Fine, move on. Sometimes it’s softer – weak documentation, unclear ownership, patchy website disclosure, thin compliance framework, or volume projections that looked made up.

Fix the file before trying again.

A practical recovery sequence looks like this:

  1. clean up the website so it matches the actual business model
  2. rewrite the business summary in normal human language
  3. rebuild the transaction flow and source-of-funds explanation
  4. tighten AML documents and internal controls
  5. check whether the entity or licensing position is the real blocker

Sometimes the issue is less about banking and more about who owns compliance internally. If nobody can answer basic AML questions on a call, banks notice. Fast.


The realistic timeline founders should expect

Not instant. Especially not for high-risk.

If your structure is clean, documents are ready, compliance is credible, and the use case fits the provider, things can move reasonably well. If any of those are off, expect delays, follow-up questions, and re-papering. Sometimes several rounds. Cross-border groups with nominee arrangements, layered holdings, crypto exposure, or gambling flows usually take more explaining, not less.

So build banking into the launch plan early. Not after the website is live and customers are waiting to deposit.


The real playbook

Here’s the short version.

Getting a SEPA IBAN for a high-risk business is rarely about finding a “friendly bank.” It’s about making your business legible to risk teams. Clean structure. Clear flows. Credible compliance. A jurisdiction that makes sense. And an application pack that answers the ugly questions before anyone asks them.

Do that, and your odds improve a lot.

Skip it, and you’ll spend months wondering why a perfectly legal business can’t get a basic euro account. Sound familiar? Yeah. I see it all the time.

Count the links if you’re wondering – yes, there are exactly four.

More insights