EST · MMXXVI
Home/Insights/Disputes/PSP and acquiring agreement: Practical Lessons for Boards
Banking, Payments & EMI Onboarding

PSP and acquiring agreement: Practical Lessons for Boards

Psp and acquiring agreement: Practical Lessons for Boards. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to

A digital-asset exchange onboards its first card-processing partner and, within three months, the acquirer terminates the agreement without notice. The fiat rails go dark. Settlement funds are held. The board discovers, too late, that the contract governing this critical relationship was not reviewed by counsel with cross-border payments experience. This is not an unusual sequence. In our practice advising crypto businesses across multiple jurisdictions, the failure point is almost always the same: the acquiring or PSP agreement was treated as a standard commercial contract rather than as a regulated instrument with its own legal architecture.

A PSP and acquiring agreement (a payment services provider or card-acquiring contract) sits at the intersection of payments regulation, financial crime compliance, card-scheme rules and ordinary commercial law. Each layer can extinguish the relationship independently. Understanding those layers before you sign – and building board-level governance around them – is the difference between a sustainable fiat corridor and a business that stalls every time a bank changes its risk appetite.

This analysis examines the legal structure of PSP and acquiring agreements, the regulatory regimes that give those contracts their teeth, the cross-border complexity that digital-asset businesses face, and the board-level lessons that follow.

What legal frameworks actually govern a PSP or acquiring agreement?

A PSP or acquiring agreement is not governed by payment regulation alone – it sits under a layered regime that most boards do not fully audit before signing. The primary regulatory layer in the European Union is the Payment Services Directive (PSD2) regime, administered through national competent authorities, which sets the conditions under which licensed payment institutions may contract with merchants. In the United Kingdom, the Financial Conduct Authority (FCA) oversees payment institution authorisation under a parallel domestic framework that has diverged from the EU position post-Brexit. In the United States, the applicable regime is a patchwork of state money-transmitter licensing (MTL) requirements, federal Bank Secrecy Act obligations administered by FinCEN, and card-scheme rules set by Visa and Mastercard at the private-contract level.

Critically, every card-scheme contract incorporates the schemes' own operating regulations by reference. Those regulations are not public in full, they change periodically, and they explicitly prohibit acquiring for merchant category codes associated with digital-asset trading in many circumstances. A PSP that cannot acquire for your business under scheme rules will terminate, regardless of what the bilateral contract says about notice periods.

The acquiring agreement itself typically contains: a merchant classification clause; an acceptable-use or prohibited-activities schedule; reserve and holdback provisions; a rolling termination right; and a chargeback-liability clause. Each of these is a potential exit route for the acquirer. Boards that treat the prohibited-activities schedule as boilerplate discover its importance when the acquirer invokes it to freeze settlement funds pending termination.

In our cross-border practice, we have seen boards sign agreements that appeared commercially sound but contained prohibited-activities language broad enough to cover any business transacting in digital assets – including businesses that held valid VASP registrations in their home jurisdiction. The regulatory licence is necessary. It is not sufficient to protect the commercial relationship.

Why do digital-asset businesses face higher termination risk than conventional merchants?

Digital-asset businesses occupy the highest-risk tier in the risk-appetite frameworks of most card acquirers, because chargeback rates, fraud exposure and regulatory uncertainty interact in ways that conventional merchant categories do not. Three structural factors drive this.

First, chargebacks. Card transactions for crypto purchases are irreversible at the asset level but reversible at the card level. A cardholder who initiates a chargeback after a token purchase has received value that cannot be clawed back. The acquirer absorbs the loss. Acquirers price this risk through elevated rolling reserves, or they decline the category entirely.

Second, regulatory uncertainty. An acquirer operating across multiple jurisdictions cannot predict whether its crypto-merchant clients will remain licensed in every market they serve. A VASP that loses its registration – or that never had one – becomes an unacceptable counterparty overnight. Acquirers build broad termination rights to protect themselves from this. The termination right is almost always wider than the actual risk.

Third, card-scheme pressure. Visa and Mastercard periodically update their merchant-category-code rules for digital assets, and those updates can reclassify a previously permissible merchant into a prohibited or high-risk tier without prior commercial notice to the acquiring bank. The acquirer's contract with the scheme gives the scheme priority. The merchant's contract with the acquirer does not override it.

The cross-border dimension amplifies each of these. A digital-asset exchange with users in twenty jurisdictions may be processing transactions that are lawful in most of them but prohibited by card rules in others. The acquirer sees the aggregate risk. The merchant sees jurisdiction-by-jurisdiction legality. That gap in framing is the source of most disputes we encounter.

For a scoped review of your existing PSP or acquiring agreement before renewal or dispute, contact OBOLUS at info@oboluslaw.com. The process above describes the standard risk architecture. Your specific entity structure, user-base geography and licence position change the analysis materially. Map your options.

What are reserve and holdback provisions, and why do they matter at board level?

Reserve and holdback provisions are the mechanism by which an acquirer retains a portion of settlement funds as security against chargebacks and regulatory risk – and they are the primary instrument through which a dispute becomes a liquidity crisis. A board that has not read these provisions before signing does not know the actual cash position of its payments operation.

A typical rolling reserve requires the acquirer to withhold a defined percentage of gross processing volume for a defined period. On termination, the acquirer may extend the holdback period substantially – often to a period that reflects the maximum chargeback window under the relevant card scheme. For digital-asset merchants, that window is not always the standard sixty to one hundred and twenty days that applies to conventional e-commerce. Acquirers frequently negotiate extended holdback provisions for high-risk merchant categories.

The practical consequence: a crypto business processing material card volume may have a six or seven-figure sum in reserve at any given time. On termination, that sum is not released immediately. It sits with the acquirer until the holdback period expires or until the parties negotiate a release. In our practice, we have seen merchants wait many months for reserve funds to be released after termination, during which the funds are effectively unavailable for operations.

Board-level governance should treat the rolling reserve as a contingent liability that affects working-capital planning. The CFO needs to know the maximum reserve exposure under the contract, the conditions for early release, and the acquirer's discretion to increase the reserve percentage on risk grounds. These are not questions for the payments operations team alone.

How does cross-border structure affect the PSP agreement?

For a digital-asset business structured across multiple entities and jurisdictions – as most serious operators are – the PSP agreement raises questions that a single-entity analysis misses entirely. The contracting entity, the jurisdiction in which it is licensed, the jurisdiction of the acquiring bank, and the jurisdictions where users transact can all differ. Each of those differences creates legal exposure.

The contracting entity question is fundamental. Acquirers require the contracting merchant to be the licensed entity. If your group structure separates the licensed VASP from the entity that operates the exchange front-end, the acquirer may be contracting with an entity that does not hold the relevant VASP registration. That mismatch is a ground for termination and, in some jurisdictions, a regulatory breach.

The jurisdiction of the acquiring bank matters because the contract is typically governed by the law of that jurisdiction. A Lithuanian CASP (Crypto-Asset Service Provider, now being authorised under MiCA, the EU's Markets in Crypto-Assets Regulation) contracting with a Maltese or Estonian acquiring institution faces a contract governed by the law of that acquiring institution's home member state. Disputes are resolved under that law, in that jurisdiction's courts – not under the law the merchant assumed applied.

The user-geography question is the most frequently overlooked. A VASP licensed in one EU member state can passport its service to other member states under MiCA. Whether its card acquirer can support that geographic footprint is a separate question, determined by the acquirer's own scheme agreements and risk appetite. Operators we advise routinely discover that their acquirer has quietly geo-blocked certain markets after a scheme policy update, without formal notification to the merchant.

For businesses connecting EU fiat rails to a non-EU entity – for example, a BVI or Cayman holding company that operates through an EU-licensed subsidiary – the structure of inter-company flows must be disclosed to and accepted by the acquirer. Undisclosed beneficial structures are a termination ground in almost every PSP agreement we have reviewed.

How does EMI onboarding compare to acquiring, and when should a board pursue it?

An EMI (Electronic Money Institution) relationship offers a different legal architecture than a card-acquiring agreement, and for certain digital-asset business models it is the more appropriate fiat corridor. Understanding the difference is a board-level decision, not an operations-team decision.

An EMI is licensed under the relevant e-money regime – in the EU, this means authorisation under the Electronic Money Directive framework, supervised by a national competent authority. In the UK, the FCA supervises EMIs separately from payment institutions. An EMI can issue IBANs, hold client funds as e-money and execute credit transfers. This is operationally distinct from card acquiring, which is purely a card-transaction processing service.

For a digital-asset exchange, the practical question is whether the business needs to process card-funded purchases (acquirer), hold fiat on behalf of clients pending conversion (EMI or safeguarding arrangement), or move fiat between clients and banking counterparties (payment institution). Most exchanges need some combination of all three, which means they need relationships with licensed entities across multiple categories.

EMI onboarding for crypto clients is subject to the same risk-appetite dynamic as card acquiring, but the termination risk profile differs. An EMI that holds client funds under a safeguarding obligation has regulatory constraints on how quickly it can terminate and return funds. A card acquirer does not hold client funds in the same sense – it processes and settles them. This distinction matters when modelling the worst-case scenario on relationship breakdown.

In our cross-border practice, we have assisted several exchanges in mapping the optimal combination of acquiring, EMI and banking relationships across EU and non-EU jurisdictions. The result is not a single agreement with a single counterparty – it is a payment architecture with redundancy built in at each layer.

If a prior application stalled or an existing banking or EMI relationship has been terminated, a structural review may identify the root cause and the route back. Reach OBOLUS at info@oboluslaw.com. Map your options.

How do AML and the Travel Rule affect the PSP relationship?

Anti-money laundering obligations are a central, not peripheral, feature of the PSP relationship for digital-asset businesses, because the acquirer is itself a regulated entity with its own AML obligations toward its merchant clients. The acquirer is not simply processing payments – it is conducting ongoing due diligence on the merchant as a business customer.

Under the FATF Recommendations, specifically Recommendation 15 concerning virtual assets, VASPs are expected to implement controls equivalent to those of financial institutions. Acquirers and EMIs look for evidence that the VASP meets this standard. A VASP that cannot demonstrate adequate KYC and transaction-monitoring procedures is an elevated risk to the acquirer's own regulatory standing. That risk is managed by termination.

The Travel Rule – the obligation to pass originator and beneficiary identification data with a virtual-asset transfer – adds a further layer. An acquirer or EMI that processes fiat transactions which fund or are funded by on-chain transfers needs to understand how the VASP handles Travel Rule compliance. Where the VASP cannot demonstrate compliance, the fiat counterparty faces indirect exposure to financial crime risk that its regulators will not accept.

For boards, this means that AML governance at the VASP level is a commercial prerequisite, not just a regulatory obligation. Deficiencies in the VASP's own AML framework become visible to the acquirer during periodic due diligence reviews. In our practice, we have seen well-structured exchanges lose their acquiring relationships not because of their own conduct, but because their AML documentation was inadequate to satisfy the acquirer's compliance team at review time.

The cross-border dimension of AML compliance is particularly acute for exchanges with users in high-risk jurisdictions. Acquirers maintain their own lists of jurisdictions they will not process transactions to or from. Those lists are not always consistent with FATF's own high-risk country list. A VASP that onboards users from a jurisdiction on the acquirer's internal list – but not on FATF's – may trigger a termination it did not anticipate.

Which acquiring approach suits which operator profile?

There is no single right answer to the question of how a digital-asset business should structure its fiat rails, because the optimal approach depends on entity structure, geographic footprint, product type and risk profile. The following profiles capture the most common decision points we encounter.

Profile A – Early-stage exchange with a single EU licence. This operator has a MiCA CASP authorisation or is in the MiCA transition period, serves primarily EU users and has limited transaction volume. The appropriate route is a single acquiring relationship with an EU-licensed acquirer that has documented crypto-merchant capacity, supplemented by an EMI relationship for client-fund holding. The key risk is over-reliance on one acquirer; the timeline to establish a second acquiring relationship, if the first is terminated, can extend to several months.

Profile B – Mid-market exchange with multi-jurisdiction user base. This operator serves users across EU and non-EU jurisdictions, has a licensed entity in one or more jurisdictions and processes material card volume. The appropriate structure is a primary EU acquirer for EU card volume, a separate non-EU acquiring relationship (potentially through a partner or sub-acquirer) for non-EU volume, and an EMI in a jurisdiction with a favourable fiat-corridor environment. The key risk is inter-entity flow disclosure – each acquirer must understand the group structure.

Profile C – Institutional exchange or custodian with low retail card volume. This operator has limited card-transaction volume but significant SWIFT and SEPA fiat flow. The acquiring agreement is secondary; the primary need is a banking relationship with a correspondent that accepts digital-asset business and a payment institution licence or EMI that can execute large-value transfers. The key risk is correspondent-bank de-risking, which can interrupt SWIFT access without warning.

Profile D – Token issuer without an exchange function. This operator does not process retail card transactions but raises fiat in connection with a token sale or fund close. The acquiring question is largely irrelevant. The relevant payment-law questions concern the treatment of the fiat raised – whether it constitutes deposits, e-money or funds held under a client-money regime – and whether the issuer needs its own payment licence or can rely on a third-party payment institution. Timeline to structure: varies by jurisdiction and product type.

A common assumption boards should revisit: "Our licence covers the payment side too"

A common assumption among digital-asset boards is that a VASP registration or CASP authorisation provides sufficient regulatory cover for the payment-services aspects of their operation. It does not. A VASP licence authorises the virtual-asset service. Payment services – receiving and transmitting funds, issuing e-money, acquiring card transactions – require separate authorisation under the applicable payments regime.

In practice, this means a licensed exchange that processes card deposits without holding a payment institution licence or working through a correctly licensed acquirer is operating a payment service without authorisation. In the EU, this is a breach of the applicable national law implementing the payment services directive. In the UK, it would be a breach of the Payment Services Regulations. In the United States, it could constitute unlicensed money transmission at the state level, with significant enforcement consequences.

The second common assumption is that a single offshore licence – a BVI VASP registration, for example – is sufficient to serve clients globally. The BVI VASP Act 2022 registers entities for VASP activities. It does not authorise payment services in the EU, the UK or the United States. A BVI-registered entity processing EU-user card transactions through a European acquirer is not protected by its BVI registration from EU payment-services enforcement action. Operators we advise routinely underestimate the gap between their offshore VASP registration and the full regulatory stack they need to operate across their intended user base.

The third assumption – that the acquiring agreement can be renegotiated after termination – consistently proves wrong in practice. Acquirers that terminate crypto merchants rarely reverse the decision. The practical consequence of termination is the need to build a new acquiring relationship from scratch, which takes time and requires a demonstrably improved regulatory and compliance position. Boards that manage this risk proactively – by maintaining two acquiring relationships at all times – avoid the operational crisis that follows single-point-of-failure terminations.

What a dispute over a PSP termination looks like in practice

In a recent matter, a European digital-asset exchange retained OBOLUS after its primary card acquirer invoked the prohibited-activities schedule and suspended settlement without notice. The exchange held a valid CASP authorisation under the transitional MiCA regime and had operated under the agreement for more than a year without incident. The trigger was a card-scheme policy update that reclassified a subset of the exchange's transaction types into a prohibited category. The acquirer had not notified the exchange of the reclassification.

We reviewed the contract and identified that the acquirer's termination was technically premature under the notice provisions, and that a portion of the reserve holdback was subject to an early-release condition the acquirer had not applied. We engaged directly with the acquirer's legal team and achieved release of the available reserve within a matter of weeks. We also identified the structural deficiency – the exchange was contracting through a non-licensed subsidiary – and advised on the entity restructuring required to establish a replacement acquiring relationship on defensible terms. The exchange was processing card transactions through a replacement acquirer within a period that the board had considered impossible at the outset of the engagement.

The lesson the board took: the time to audit the acquiring agreement is before termination, not after. The legal leverage available to a merchant is significantly greater when it acts before the acquirer has completed the termination process.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto business accounts primarily because of regulatory risk, AML compliance concerns and card-scheme pressure. Most correspondent banking frameworks treat digital-asset businesses as high-risk by default. A bank that cannot satisfy its own regulator that it has adequate controls over a crypto-company client will exit the relationship rather than accept enforcement exposure. Inadequate KYC documentation, unclear beneficial ownership, unlicensed payment activity and geographic user-base risk are the most common specific triggers we encounter in our practice.

How can a VASP onboard with an EMI?

A VASP (virtual asset service provider) can onboard with a licensed EMI by meeting the EMI's customer due-diligence requirements, which typically include: a VASP registration or CASP authorisation from a recognised jurisdiction; a full AML/KYC policy pack; a compliance officer designation; a beneficial ownership disclosure meeting the EMI's standards; and evidence of Travel Rule implementation. The EMI will conduct ongoing monitoring. VASPs that approach EMI onboarding with complete documentation significantly improve their success rate and shorten the onboarding timeline compared with underprepared applicants.

What does client-money safeguarding require?

Client-money safeguarding requires a licensed payment institution or EMI to hold client funds separately from its own funds, in a designated account with a qualifying credit institution or through an insurance or guarantee product meeting the applicable regime's standards. Under the EU payments framework, specific safeguarding methods and reporting obligations apply. In the United States, state MTL regimes impose their own permissible-investment and surety-bond requirements. Digital-asset businesses that hold fiat on behalf of clients prior to a conversion or withdrawal must understand whether their structure triggers these obligations – and in most cases it does.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums. We map the licence, banking and payment architecture across operating, custody and payment layers before you commit – not after the rails go dark. To discuss your situation, contact info@oboluslaw.com.

By Glen Sorensen, Disputes & Recovery Analyst – specialist in PSP termination disputes, reserve-fund recovery and cross-border payment-architecture analysis for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours