Montenegro Banking & Compliance

Why Your Crypto Company Cannot Get a Bank Account — and What Actually Answers It

The account problem is a compliance problem. Article 53c, the travel rule in Article 40f and the passivisation power explain what banks react to.

Rohat Kahraman· 20 August 2026Updated · 20 August 2026
Cover illustration: the compliance layer behind a crypto company's bank account in Montenegro

Everyone in this market has the story. The company is incorporated, the register entry is done, the founders are respectable, and the bank will not open an account — or opens one and closes it eight months later without a reason anybody will put in writing.

It is easy to read that as prejudice, or as institutional laziness. It is usually neither. Almost all of it becomes legible once you read what the law requires the other side to do, and most of those requirements are new: they arrived with the March 2025 amendments that created the register in the first place.

This piece is about the compliance mechanics behind the account decision. The general difficulty of opening accounts in Montenegro, and the payment mechanics of a property purchase, are covered separately — the account-opening problem and paying for property, transfers and AML — and are not repeated here.

You are not only a customer. You are an obliged entity.

Start with the status, because it reframes the conversation.

Crypto-asset service providers are point 12 of the list of obliged entities in Article 4(2) of the Zakon o sprječavanju pranja novca i finansiranja terorizma, supervised by the Capital Market Commission under Article 131(1)(3).

That means when you sit down with a bank you are not a retail applicant explaining an unusual business. You are a regulated counterparty with your own statutory AML obligations, your own licensed compliance officer, and your own supervisor. Presented properly, that is an argument in your favour — and most crypto applicants never make it, because they arrive with a business deck rather than a compliance file.

Article 53c: why the euro leg is the hard part

Here is the provision that explains more account refusals than any other, and almost nobody outside compliance departments has read it.

Article 53c applies to cross-border correspondent relationships that involve the performance of crypto-asset services — advisory services aside — with a respondent that has no seat in Montenegro and provides similar services, including crypto transfers. On top of the ordinary correspondent duties in Article 53, the provider must:

  1. establish whether the respondent holds an operating licence or is registered;
  2. collect enough information to fully understand the nature of the respondent's business, and assess its reputation and the quality of supervision over it, on the basis of publicly available information;
  3. assess the respondent's AML/CFT controls;
  4. obtain written approval from senior management before establishing a new correspondent relationship;
  5. document the responsibilities of each party in the relationship;
  6. as regards pass-through crypto accounts, satisfy itself that the respondent has verified identity and applied enhanced due diligence to clients with direct access to the correspondent's accounts, and can supply the relevant data on request.

Read that as a bank rather than as an applicant. Point 4 alone means the decision is not the branch manager's: a new crypto-touching correspondent relationship requires a documented senior-management sign-off. Point 2 means someone must be able to explain your business well enough to write it down. Point 6 means that if your model involves clients with direct access, the diligence obligation travels down to them.

None of that is a reason to refuse you. All of it is a reason why "we'll get back to you" takes months, and why an incomplete answer stops the file rather than slowing it.

The exclusion inside Article 53c, and who benefits from it

There is a carve-out in the opening words of Article 53c that is easy to read past and worth a great deal to one type of business.

The correspondent-relationship regime applies to relationships involving the performance of crypto-asset services other than the provision of advice on crypto-assets. Advisory services are expressly outside it.

Put that next to the scope rule from the first article in this series. Advice on crypto-assets is item eight on the statutory list of services, so an advisory-only firm is inside the register and is an obliged entity — but it sits outside the Article 53c correspondent layer, because it does not hold client assets or move them.

Commercially that is a meaningful asymmetry, and it runs in the direction people do not expect. The advisory firm carries the registration obligation, the AML officer, the internal acts — and a materially simpler banking conversation, because the counterparty is not being asked to run an Article 53c file on it.

For a firm still designing its model, that is worth knowing before the model is fixed rather than after. Whether you touch client assets is not only a licensing question and a risk question. It decides which regime your future bank has to apply to you.

Article 40f: the data that must travel with every transfer

The second thing a serious counterparty will ask about is whether you can actually comply with the transfer rules — because if you cannot, their exposure runs through you.

Article 40f requires the sender's crypto-asset service provider, when executing a transfer of crypto-assets, to provide data on both the sender and the beneficiary. For the sender that means:

  • name;
  • address or registered seat, including the name of the state, identity document number, personal or company registration number, or date and place of birth;
  • the distributed-ledger address, where the transfer is registered on a DLT network, together with the crypto-asset account number if one exists and is used to process the transaction;
  • the crypto-asset account number, where the transfer is not registered on a DLT network;
  • the legal entity identifier (LEI), where the relevant message format has the field and the sender has supplied it.

This is infrastructure, not paperwork. A provider that cannot attach these fields programmatically is not going to satisfy a correspondent, and no amount of relationship management substitutes for it.

Self-hosted wallets get their own layer

Transfers to and from self-hosted addresses attract additional measures: verifying the identity of the sender or beneficiary, or of the beneficial owner behind them — including by relying on third parties; requesting additional information on the origin and destination of the transferred crypto-assets; enhanced continuous monitoring of those transactions; and further measures to mitigate money-laundering, terrorist-financing and targeted-financial-sanctions risks, including proliferation financing.

The supervisory authority under Article 131(1)(3) is to issue guidelines on those measures and on the criteria and means for identifying and verifying the parties to self-hosted transfers, taking account of the latest technological developments.

For a firm whose product deliberately supports withdrawals to user-controlled wallets, that is the paragraph to design around before launch rather than after the first supervisory question.

Article 40c: your registration can be switched off

The final piece is the one that most changes how a bank looks at your file, because it means your registered status is not a fixed fact.

Article 40c sets out when a provider is deleted from the register. The grounds include:

  • notifying the supervisor that it will no longer provide crypto-asset services;
  • having been registered on the basis of untrue or inaccurate documentation, or misrepresented facts;
  • ceasing to meet the repute condition;
  • failing to perform the obligations under Article 40f — the transfer-data rules above;
  • not providing crypto-asset services on the territory of Montenegro.

And before deletion there is an interim state. Where the supervisor suspects one of grounds two to five, it passivises the provider's status in the register and notifies it. Passivisation lasts until the supervisor determines whether a ground is met — deleting the provider if it is, removing the passivisation if it is not. Critically: a provider may not provide crypto-asset services while passivised.

A decision to delete may be challenged by administrative dispute.

Two consequences follow. First, failure on the travel rule is not merely a supervisory finding — it is an express ground for removal from the register. Second, the last ground kills a common idea: a dormant registration is not a shelf asset. Registering in order to have a Montenegrin entry available, while actually operating elsewhere, is itself a ground for deletion.

What the bank is reacting toWhere it comes from
Senior-management sign-off before onboarding youArt. 53c(4)
Needing to fully understand and document your businessArt. 53c(2), (5)
Questions about clients with direct account accessArt. 53c(6)
Whether transfer data can be attached programmaticallyArt. 40f
Extra scrutiny of self-hosted wallet flowsself-hosted transfer measures
Whether your registration could be switched offArt. 40c passivisation and deletion

What to put in front of a bank

The file that works is not a pitch deck. On the evidence of the provisions above, it is closer to this: your register entry and the exact services it covers; the identity and licence of your AML compliance officer; your internal acts, aligned as the law requires; a written description of your business that someone else could adopt for their own file under Article 53c(2); your travel-rule implementation, described technically; your policy on self-hosted wallet transfers; and a clear statement of which clients, if any, have direct access to accounts.

That is what the other side has to produce internally in order to say yes. Handing it to them is not over-disclosure. It is removing the reason for the delay.

What I could not verify

Two limits, stated rather than glossed.

I found no penalty provision keyed specifically to the crypto registration article, so no figures appear here. Deletion and passivisation are the consequences the text does spell out, and they are commercially more serious than most fines anyway.

The supervisor's guidelines on self-hosted transfers are contemplated by the statute. Whether they have been issued, and what they say, is a matter to check with the Capital Market Commission at the time you build the policy rather than to infer from the enabling provision.

The arithmetic

The costs here sit in the wrong order for most founders. Incorporation is quick, the register entry is a defined file, and the bank account — the thing everyone assumes is administrative — is the item that decides whether the business can operate at all.

A crypto company with a registration and no banking is not a business with a problem. It is a business that cannot settle, cannot pay staff locally and cannot demonstrate substance. And the material that unlocks the account is largely the same material the register application already required, assembled for a different reader.

Building it once, in a form both readers accept, is the cheapest sequencing available.

What to send, and when

Send your register entry and the services it covers, a plain description of your transaction flows including whether you support withdrawals to self-hosted wallets, and where your settlement and correspondent relationships sit today. That is enough to say what a Montenegrin bank will have to satisfy internally and what is missing from the file.

RoNa Legal advises foreign clients on Montenegrin law; representation before Montenegrin authorities and courts is conducted together with advocates entered in the register of the Bar Association of Montenegro. See our fintech and crypto practice or reach us through contact. Earlier in this series: the register and who must be in it, what registration obliges you to do, and why the register is not a MiCA licence.

Frequently asked questions

Why do banks refuse crypto companies in Montenegro?

Usually because of what the law requires of them rather than prejudice. Article 53c imposes specific duties on cross-border correspondent relationships involving crypto-asset services, including written senior-management approval before establishing the relationship.

Does being registered help?

Yes, if you use it. Crypto-asset service providers are obliged entities under Article 4(2) point 12, supervised by the Capital Market Commission, with their own AML officer and internal acts. That makes you a regulated counterparty rather than an unexplained applicant.

What exactly must a correspondent check?

Under Article 53c: whether the respondent is licensed or registered; enough information to fully understand its business, reputation and quality of supervision from public sources; its AML controls; written senior-management approval before the relationship starts; documented responsibilities of each party; and, for pass-through crypto accounts, that identity was verified and enhanced due diligence applied to clients with direct access.

What is the travel rule in Montenegro?

Article 40f requires the sender's provider to supply data on the sender and the beneficiary with each transfer — name, address or seat including the state, identity or registration number or date and place of birth, the distributed-ledger address and crypto account number where applicable, and the LEI where the message format provides for it.

What if we support withdrawals to self-hosted wallets?

Additional measures apply, including verifying the identity of the sender, beneficiary or beneficial owner, requesting additional information on the origin and destination of the assets, and enhanced continuous monitoring. The supervisor is to issue guidelines on how this is done.

Can our registration be suspended?

Yes. Under Article 40c the supervisor passivises the status where it suspects a ground for deletion, and a provider may not provide crypto-asset services while passivised.

What can get us deleted from the register?

Notifying that you will cease services; having been registered on untrue or inaccurate documentation or misrepresented facts; ceasing to meet the repute condition; failing to perform the Article 40f transfer obligations; and not providing crypto-asset services on the territory of Montenegro.

Can we register now and start operating later?

Not indefinitely. Not providing crypto-asset services in Montenegro is itself a ground for deletion, so a dormant registration held as a shelf asset is exposed.

Can we challenge a deletion?

An administrative dispute may be brought against a decision to delete from the register.

What should we hand the bank?

The register entry and its service scope, the AML officer's identity and licence, aligned internal acts, a written business description usable in the bank's own Article 53c file, the travel-rule implementation described technically, the self-hosted wallet policy, and whether any clients have direct account access.

Are there fines for operating without registration?

No figures are given here. I could not tie a penalty provision specifically to the crypto registration article in the consolidated text, and deletion or passivisation are the consequences the law does set out.