Insights

Why banks reject high-risk business account applications

··Payments

Banks reject high-risk business account applications for one narrow legal reason: the compliance team could not complete customer due diligence to the standard the law demands, so it was obliged to walk away. Everything else — your industry, your ownership chart, your unexplained first deposit — is an input into that single conclusion. Understanding which input failed is what makes a second application worth filing.

Scope of this article. The analysis below works through the EU framework, because it is the most explicitly codified and the one most applicants meet first. The same failure modes recur under the UK, US and UAE regimes — the rulebook changes, the reasons a file fails do not. See how it differs outside the EU, or read about account opening across all of these markets.

Key takeaways

  • Under Article 14(4) of Directive (EU) 2015/849, a bank that cannot complete due diligence must not open the account. Refusal is not discretion — at that point it is a legal obligation.
  • The bank usually will not tell you why. Article 39 of the same directive prohibits tipping off where a suspicion report has been filed, and silence is the safe default for the compliance officer.
  • EU supervisors have pushed back on blanket refusals. EBA Guidelines EBA/GL/2023/04 require institutions to assess you individually, to consider risk-mitigating measures before rejecting you, and to document their reason.
  • Companies have no legal right to a bank account in the EU. The right of access under the Payment Accounts Directive is reserved for consumers — natural persons acting outside a trade or business.
  • A refusal is a file problem far more often than a business problem. The same company, with the same activity, is routinely approved once the evidence is assembled the way a compliance analyst reads it.

What “high risk” actually means inside the bank

“High risk” is not a judgement about whether your business is legitimate. It is a classification that determines how much work the bank must do on you, and how much that work costs relative to what your account will earn the bank.

Directive (EU) 2015/849 requires every obliged entity to apply customer due diligence: identify and verify the customer, identify and verify the beneficial owner, assess the purpose and intended nature of the relationship, and monitor it on an ongoing basis (Article 13(1)). Where the risk is higher, Article 18 requires enhanced due diligence, and for relationships touching high-risk third countries Article 18a adds specific obligations, including senior-management approval before the relationship is established.

So a “high-risk” label means: a more senior person has to sign off, more evidence has to be gathered, and the file has to be revisited more often. If your projected revenue to the bank does not cover that, the commercially rational answer is no — before the analyst has even formed a view about you. This is why perfectly clean iGaming operators, affiliate networks and supplement brands are refused by institutions that never intended to serve them in the first place. It is also why choosing the right provider before you apply matters more than the quality of the application itself.

The rule that forces the refusal

The operative provision is short. Article 14(4) of Directive (EU) 2015/849 states that where an obliged entity is unable to comply with the customer due diligence requirements, “it shall not carry out a transaction through a bank account, establish a business relationship or carry out the transaction, and shall terminate the business relationship.”

Read that carefully. The trigger is not “the customer looks risky”. The trigger is inability to complete due diligence. In practice that means one of the four CDD limbs could not be closed to the analyst’s satisfaction:

  • The customer could not be verified — mismatched registry data, documents that do not reconcile, an entity whose filings are overdue.
  • The beneficial owner could not be established — the chain runs through a jurisdiction that does not publish ownership, or stops at a nominee.
  • The purpose of the relationship was not credible — the stated business model does not explain the expected flows, counterparties or currencies.
  • The source of funds or wealth was not evidenced — for a newly incorporated company, this is the single most common failure point, because there is no trading history to point at.

If you can identify which of those four failed, you have a second application worth filing. If you cannot, you are guessing.

Why the bank will not tell you the real reason

Two mechanisms produce the wall of silence.

First, Article 39(1) of Directive (EU) 2015/849 prohibits obliged entities and their staff from disclosing to the customer that information has been transmitted to the financial intelligence unit, or that a money-laundering investigation is being carried out. Where a suspicion report has been filed, the bank is legally barred from explaining itself.

Second, even where no report was filed, compliance functions default to silence because distinguishing the two situations in a written explanation is itself informative. A generic “we are unable to proceed at this time” is the safe answer in both cases.

A refusal letter that says nothing is not evidence of a suspicion report. It is evidence that the bank has one refusal template.

There is, however, one thing the bank is expected to tell you. Paragraph 22 of EBA/GL/2023/04 provides that when institutions communicate a decision to refuse or terminate a business relationship with a customer or potential customer, they must advise that person of their right to contact the relevant competent authority or designated alternative dispute resolution body, and must provide the contact details. If your refusal letter omitted that, the institution has not followed the guidelines.

The risk factors the law tells the bank to look for

Annex III to Directive (EU) 2015/849 sets out a non-exhaustive list of factors indicating potentially higher risk. It is worth reading as a checklist of what your file will be scored against, because it maps almost exactly onto the reasons applications fail.

Category Factors named in Annex III What it looks like in a refused file
Customer Relationship conducted in unusual circumstances; personal asset-holding vehicles; nominee shareholders or bearer shares; cash-intensive businesses; ownership structure unusual or excessively complex given the nature of the business A three-layer holding chain over a single operating company with two employees. The structure may be entirely tax-driven and lawful — but the bank must ask why, and “our adviser suggested it” is not an answer.
Product, service, transaction or delivery channel Private banking; products favouring anonymity; non-face-to-face relationships without safeguards such as regulated electronic identification; payments received from unknown or unassociated third parties; new products and technologies Expected inflows from payment aggregators or affiliate platforms the bank cannot map to your contracts. Third-party settlement is one of the fastest routes to a decline.
Geography Countries identified by credible sources as lacking effective AML/CFT systems, or as having significant levels of corruption or other criminal activity Directors, beneficial owners, customers or suppliers located in a jurisdiction the bank’s screening tool flags — even where the company itself is EU-incorporated.
Residence and citizenship by investment A third-country national applying for residence rights or citizenship in exchange for capital transfers, property purchase, government bonds or corporate investment A founder whose identity documents were obtained through an investment programme. This became an express Annex III factor and now requires deliberate handling in the file — a point worth planning for alongside any residency or citizenship by investment application.

Note what is not on that list: your industry. Gambling, adult, nutra, crypto and affiliate marketing are not named as higher-risk factors in Annex III. Sector risk enters through the bank’s own risk assessment and through the EBA ML/TF Risk Factors Guidelines (EBA/GL/2021/02), not through a statutory blacklist of industries. That distinction is the basis of every successful appeal.

What the bank is supposed to do before saying no

This is the part most applicants do not know, and it is the most useful leverage available after a refusal.

EBA/GL/2023/04, published on 31 March 2023, was written specifically to curb unwarranted de-risking. Its operative paragraphs require, in substance:

  • Paragraph 9 — institutions must differentiate between the risks associated with a category of customers and the risks associated with individual customers belonging to that category.
  • Paragraph 10 — policies and controls must not result in “the blanket refusal or termination of business relationships with entire categories of customers” assessed as higher risk.
  • Paragraph 11 — institutions must set out in their policies the criteria on which a relationship may be rejected, and all the options for mitigating higher risk that they will consider before rejecting a customer, including adjusting monitoring intensity and applying targeted product restrictions.
  • Paragraph 12 — before deciding to reject, institutions “should satisfy themselves that they have considered and rejected all possible mitigating measures that could reasonably be applied in the particular case”.
  • Paragraph 14 — institutions must document any decision to refuse a relationship and the reason for it, and be prepared to produce that documentation to their supervisor on request.

The guidelines apply three months after publication in all EU official languages (paragraph 8). They bind institutions through their national supervisors, not through a private right of action — you cannot sue your way into an account. But they change the conversation. A well-drafted response that offers the mitigations the bank is supposed to have considered first — lower turnover limits, restrictions on third-country transfers, a narrower product set to start — is materially harder to refuse a second time than a bare re-application.

Do you have a right to a business bank account?

No. This is the most common misconception among refused founders, and it is worth being blunt about.

The Payment Accounts Directive (2014/92/EU) creates a genuine right of access to a payment account with basic features — but only for consumers. Article 2 defines a consumer as “any natural person who is acting for purposes which are outside his trade, business, craft or profession”, and recital 12 states expressly that accounts held by businesses, “even small or micro enterprises, unless held in a personal capacity, should fall outside the scope of this Directive”.

Consumers who are refused must be told the specific reason in writing and free of charge, unless disclosure would be contrary to national security or anti-money-laundering objectives. Companies get none of that. Your leverage is the EBA guidelines and the commercial relationship — not a statutory entitlement.

How to rebuild the file after a refusal

Treat the second application as a different exercise from the first. The objective is not to re-argue that you are legitimate; it is to remove the specific ambiguity that stopped the analyst.

  1. Diagnose which CDD limb failed. Re-read every question the bank asked before it went quiet. The last question is usually the one that was not answered well enough — most often source of funds, or the commercial rationale for a structure.
  2. Fix the structure before the file. If the ownership chain is complex without a defensible commercial reason, no amount of drafting will rescue it. Simplifying one layer is often worth more than fifty pages of explanation, and it is the point at which how the company was incorporated comes back into play.
  3. Evidence source of funds with documents, not narrative. Bank statements, signed contracts, audited accounts, a share sale agreement, a dividend resolution. For a newly incorporated company, evidence the shareholder’s wealth rather than the company’s, and show the paper trail from that wealth into the subscription capital.
  4. Write the business description for the analyst, not the investor. Name your counterparties, the currencies, the expected monthly volume, the payment rails, and who pays you. A description that lets the analyst predict your first six months of transactions is what closes the “purpose and intended nature” limb.
  5. Offer mitigations proactively. Turnover caps, restrictions on transfers to and from higher-risk third countries, a limited product set for the first year. These are the measures paragraph 11 tells the bank to consider — offering them signals you understand the file.
  6. Apply where your profile is actually onboarded. A refusal from an institution with no appetite for your sector tells you nothing about your file. Pre-approval soundings before a formal application avoid building a history of declines that later applicants’ screening tools will see.

That last point matters more than it sounds. Repeated formal applications leave traces, and a pattern of declines becomes its own risk factor. This is the core of what our corporate account opening service does: match the profile to institutions that genuinely onboard it, then build a compliance file that survives contact with an analyst.

How long a corporate account opening realistically takes

There is no regulated timetable for corporate onboarding — the Payment Accounts Directive’s deadlines apply to consumer basic accounts, not companies. In practice, timelines are driven by how many rounds of questions the file generates, which is itself a function of how complete it was on day one.

A straightforward EU operating company with a resident director and a clean, documented source of funds typically moves faster than a multi-layer holding structure with non-resident owners and third-party settlement flows. Enhanced due diligence under Article 18 adds time by design, because it requires additional evidence and, for high-risk third-country exposure under Article 18a, senior-management approval before the relationship can be established. Any provider quoting you a fixed number of days without having seen your ownership chart is quoting a marketing figure.

What changes in 2027

The EU has replaced the directive-based regime with a directly applicable regulation. Regulation (EU) 2024/1624 — the AML Regulation — was adopted on 31 May 2024 and, under its Article 90, applies from 10 July 2027 (with a later date of 10 July 2029 for certain obliged entities listed in Article 3, points (3)(n) and (o)).

The refusal mechanic survives essentially unchanged. Article 21(1) of the Regulation restates it: where an obliged entity is unable to comply with the customer due diligence requirements in Article 20(1), it “shall refrain from carrying out a transaction or establishing a business relationship, and shall terminate the business relationship”, and consider filing a suspicious transaction report.

What changes is uniformity. Because a regulation applies directly rather than through national transposition, the room for divergence between member states — which today lets an applicant refused in one country succeed in another — narrows. Structures that work only because of a gap between two national transpositions have a defined shelf life.

How this differs outside the EU

Everything above is written from the EU rulebook. We also open accounts in the UK, the United States, the UAE and Asia, and the underlying logic does not change: the bank must be able to complete due diligence, or it must decline. What changes is which instrument imposes that duty and who enforces it.

Market Governing framework What differs in practice
EU / EEA The Anti-Money Laundering Directives, transposed by each member state, with EBA guidelines setting supervisory expectations Harmonised in principle, but transposition and bank appetite still vary by member state
United Kingdom Money Laundering Regulations 2017, regulation 28 Same risk-based tiers — standard, simplified and enhanced due diligence — set out in a single domestic instrument
United States Bank Secrecy Act and the FinCEN Customer Due Diligence Rule, 31 CFR 1010.230 Beneficial owners of a legal entity must be identified and verified at the point the account is opened
UAE Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, which replaced the 2018 and 2019 framework A recently rebuilt regime — requirements that circulated before 2025 are no longer the current ones

We also act on openings in Singapore and Hong Kong, where the same due-diligence logic applies under each regulator’s own AML rules. Because these regimes are revised often — as the UAE example shows — we confirm the requirements that are actually in force for your profile before anything is filed.

Can a bank refuse a business account without giving a reason?

Yes. In the EU, the obligation to give a specific written reason for refusal applies to consumers under the Payment Accounts Directive, not to companies. Where a suspicion report has been filed, Article 39 of Directive (EU) 2015/849 actively prohibits the bank from explaining. However, under paragraph 22 of EBA/GL/2023/04 the institution must still tell you that you have a right to contact the relevant competent authority or alternative dispute resolution body, and provide the contact details.

Is it legal for a bank to refuse an entire industry?

Refusing every applicant in a sector without individual assessment is contrary to the EBA’s guidelines. Paragraph 10 of EBA/GL/2023/04 states that institutions should ensure their policies do not result in the blanket refusal or termination of business relationships with entire categories of customers, and paragraph 9 requires them to distinguish category risk from individual customer risk. This is a supervisory expectation enforced by national regulators, not a right you can enforce directly against the bank.

Does being refused by one bank hurt my next application?

Not automatically — banks do not share a central register of refusals. But a repeated pattern of applications and declines can surface through screening providers, adverse-media checks and the questions banks ask about prior banking relationships, and an unexplained pattern becomes a risk factor in its own right. This is the practical argument for pre-approval soundings rather than speculative applications.

What is the most common reason a newly incorporated company is refused?

Source of funds. A new company has no trading history, so the bank cannot evidence where the money came from by looking at the company. The file has to evidence the shareholder’s wealth and trace it into the subscription capital. Under Article 13(1) of Directive (EU) 2015/849 the bank must also assess the purpose and intended nature of the relationship, which a company with no operating history has to establish through contracts and a credible business description rather than through statements.

Will an EMI accept a company a bank has refused?

Sometimes, because appetite differs and some electronic money institutions are built around sectors banks avoid. But EMIs are obliged entities under the same directive and apply the same customer due diligence obligations under Article 13. A file that failed on beneficial ownership or source of funds will usually fail again. An EMI is a different risk appetite, not a lower legal standard.

Do the new EU AML rules make it harder to open an account?

Regulation (EU) 2024/1624 applies from 10 July 2027 under its Article 90 and keeps the same core mechanic — Article 21 requires an obliged entity that cannot complete due diligence to refrain from establishing the relationship. The main practical change is harmonisation: because a regulation applies directly rather than through national transposition, differences between member states narrow, and structures that depend on those differences become less reliable.

Where to go next

If you have been refused, the useful next step is a diagnosis rather than another application. We review the correspondence, identify which due diligence limb failed, and rebuild the file — then match it to institutions that actually onboard the profile. That work runs across our account opening, company formation and payments practices, and for licensed operators alongside financial licensing. If the structure itself is the problem, our note on choosing a holding jurisdiction covers the substance question banks now ask first.

This article is general information about EU anti-money-laundering rules as they stood at the date of publication, not legal advice. Bank and EMI appetite changes frequently, and the correct approach depends on your specific structure, jurisdiction and flows. Verify current requirements before filing any application.

Get in touch

Have a question on this?

Tell us about your situation and we will come back to you within one working day.

Scroll to Top