EST · MMXXVI
Home/Insights/Disputes/PSP and acquiring agreement: The Structuring Angle
Banking, Payments & EMI Onboarding

PSP and acquiring agreement: The Structuring Angle

Psp and acquiring agreement: The Structuring Angle. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Operating a crypto business without properly structured payment and acquiring agreements is one of the fastest routes to frozen rails, blocked settlements and regulatory scrutiny. A PSP and acquiring agreement (the contract between a digital-asset business and its payment service provider or card acquirer) sits at the intersection of payments law, banking regulation and crypto licensing – and the drafting choices made at the outset determine whether fiat flows are sustainable or fragile. This page maps the structuring angles that matter most, with a cross-border lens across the jurisdictions where digital-asset businesses actually operate.

Why the Structure of a PSP Agreement Matters for Crypto Businesses

A poorly structured PSP or acquiring agreement is not merely a commercial inconvenience – it is a direct legal exposure that can terminate a business's fiat access overnight. For a digital-asset operator, the agreement governs not only how card payments and bank transfers flow in and out, but also who bears liability when a transaction is flagged, how reserves are held and what triggers a termination right. Regulators and counterparty banks read these agreements carefully; so should the operator's counsel.

The core tension is this: payment service providers are themselves regulated entities. Under regimes such as MiCA and ESMA guidance for CASPs, an EMI or payment institution onboarding a crypto client absorbs reputational and compliance risk by association. The PSP therefore negotiates hard for indemnities, rolling reserves, enhanced due diligence rights and broad termination language. The crypto operator, by contrast, needs payment continuity, predictable settlement cycles and protection against unilateral account closure. These interests sit in direct tension, and the agreement is where that tension is either managed or left to explode.

In our cross-border practice, we see this tension most acutely when a company licensed in one jurisdiction – say, under the VARA regime in Dubai or under the Payment Services Act administered by the Monetary Authority of Singapore (MAS) – tries to access payment rails in a second market where its licence carries no formal recognition. The PSP in that second market applies its own risk assessment. Without a structuring argument that maps the operator's licensing, AML posture and transaction volumes clearly, the application fails or results in punitive reserve requirements.

The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. For a scoped assessment of your PSP agreement structure, contact OBOLUS at info@oboluslaw.com.

What Does the Regulated Perimeter for PSP Agreements Look Like?

The regulated perimeter for PSP and acquiring agreements in the digital-asset context is defined by the overlap of two distinct licensing regimes: the payment regime governing the PSP itself, and the crypto-asset or VASP regime governing its client. Understanding that overlap is the first structuring question every counsel must answer.

On the payment side, the PSP's obligations flow from whichever regime it operates under. In the EU, that is the Payment Services Directive framework, as interpreted and supervised by the relevant national competent authority. In the UK, the FCA's rules under the Payment Services Regulations apply, along with cryptoasset registration under the Money Laundering Regulations (MLR). In Singapore, the Payment Services Act creates graduated licence tiers administered by MAS. Each of these regimes imposes customer due diligence requirements, transaction monitoring obligations and – crucially – the right, and sometimes the duty, to terminate a relationship that poses unacceptable AML/CFT risk.

On the crypto side, the client operator's own licence status directly shapes what the PSP is permitted to do for it. A VASP (virtual asset service provider) licensed under the VARA regime, for example, is subject to VARA's rulebooks on custody, transfers and client money. If the operator's VARA licence does not extend to certain activities – say, lending or derivatives – and those activities generate payment flows routed through the PSP, the PSP may face regulatory exposure for processing those flows. The acquiring agreement must therefore be precise about which activities it covers.

The Travel Rule (the obligation to pass originator and beneficiary data with a transfer) adds a further layer. PSPs processing fiat legs of crypto transactions are increasingly expected by regulators to satisfy themselves that the VASP client has Travel Rule compliance in place for the matching on-chain leg. An agreement that is silent on this creates a compliance gap that regulators in multiple hubs – including the AIFC/AFSA in Kazakhstan and the FSRA within ADGM – are beginning to examine.

How Do Cross-Border Licensing Mismatches Create PSP Agreement Risk?

Cross-border licensing mismatches are the single largest source of PSP agreement disputes we encounter, and they arise predictably when an operator treats its home-jurisdiction licence as a global permission. It is not. A single offshore licence does not satisfy the regulatory expectations of PSPs, banks or regulators in the markets where the operator's users actually sit – and this gap exposes both parties to the agreement.

Consider the typical structure: an exchange or on-ramp operator incorporates in a jurisdiction with an accessible licensing regime – the BVI under the BVI FSC's VASP Act 2022, or the Cayman Islands under CIMA's Virtual Asset (Service Providers) Act. It then seeks a PSP relationship with a European EMI to process euro-denominated card payments for EU-based customers. The EMI's compliance team immediately faces the question: does the operator's BVI or Cayman registration satisfy the EU's AML expectations for the activities being processed? Under the MiCA/ESMA framework for CASPs, it may not, particularly if the operator is required to hold a CASP authorisation before serving EU customers at scale.

The structuring response is not simply to obtain a second licence. It requires mapping three questions before the agreement is signed: where is the entity contracting with the PSP; where are the customers whose transactions flow through that contract; and which regime's AML/CFT expectations govern each flow. When these three coordinates align, the agreement can be structured to reflect that alignment clearly, reducing the PSP's risk assessment and the likelihood of reserve escalation or termination.

We regularly advise operators building this structure across two or three jurisdictions simultaneously. The AIFC/AFSA in Kazakhstan, for example, offers a common-law digital-asset environment with banking connectivity that can function as a complement to an EU CASP authorisation – not a substitute. Understanding which flows sit in which entity, and which PSP contract governs each, is the structuring work that makes fiat access durable.

What Are the Key Clauses That Carry the Most Structural Risk?

The structural risk in a PSP or acquiring agreement concentrates in a small number of clauses that are routinely under-negotiated by crypto operators – often because the operator's counsel focuses on the licensing question and delegates the commercial agreement to a less senior reviewer. That is a mistake. The clauses below are the ones we examine first.

Rolling reserves. A rolling reserve is the mechanism by which the PSP withholds a percentage of settled funds as a buffer against chargebacks and regulatory risk. For crypto businesses, PSPs frequently set reserve percentages higher than for conventional e-commerce merchants. The structural question is not just the percentage but the release trigger: when does the reserve roll out, and on what condition? A reserve tied to the operator's ongoing compliance with "applicable law" – without a definition of that term – gives the PSP broad discretion to hold funds indefinitely if a regulatory question arises in any market. Operators should push for a defined release schedule and a narrow definition of the triggering condition.

Unilateral termination rights. Most PSP agreements include termination on notice periods measured in days, not months. For a crypto business whose fiat rails depend on a single PSP relationship, a 30-day termination notice is effectively a death sentence. Structuring counsel should negotiate for longer notice periods on termination for convenience, carve out termination-for-cause triggers with clear and exhaustive definitions, and include a transition-assistance obligation that requires the PSP to continue processing during an agreed wind-down period.

Change-of-control and sublicensing provisions. These clauses become critical when the operator is acquired, merges with another entity, or assigns its PSP agreement to a holding company restructuring. A change-of-control trigger that allows the PSP to terminate on any ownership change – without carving out group reorganizations or regulatory-driven restructurings – can block necessary corporate flexibility at the worst possible moment.

Indemnity and liability caps. PSPs routinely seek broad indemnities from crypto operators covering regulatory fines, third-party claims and AML-related losses. Counsel should ensure the indemnity is limited to losses arising from the operator's demonstrable breach of the agreement or applicable law – not from the PSP's regulatory risk profile in the abstract. Liability caps should be mutual and calibrated to the settlement flows processed, not to an open-ended exposure.

How Should a VASP Approach EMI Onboarding Strategy?

EMI onboarding for a VASP is not an application process – it is a negotiation, and the outcome depends as much on how the operator presents its regulatory and compliance posture as on the objective merits of its licence. EMIs are themselves regulated businesses with compliance costs and risk thresholds; they are not passive conduits for client money.

The first principle of a sound onboarding strategy is documentation discipline. An EMI's compliance team will ask for AML/CFT policies, KYC procedures, transaction monitoring frameworks, a description of the operator's customer base and – increasingly – evidence of Travel Rule compliance. Operators who present this material in a structured, jurisdiction-specific format materially reduce the time to a positive credit decision. Operators who respond ad hoc or who present generic documentation not tailored to the EMI's jurisdiction of incorporation tend to face repeated information requests and ultimately rejection.

The second principle is entity structure. Operators we advise routinely underestimate the importance of which legal entity sits in front of the EMI. An EU-incorporated subsidiary with a CASP authorisation (or an in-progress authorisation in a leading member state) will face a materially different risk assessment than a BVI holding company contracting in its own name. Building the right entity for the payment relationship – separate from the operating entity that holds the crypto licence, in some structures – is a form of risk engineering that EMIs appreciate because it clarifies the perimeter of what they are agreeing to process.

The third principle is counterparty diversification. A single EMI relationship for all fiat flows is a concentration risk that no well-structured business should accept. Operators should pursue at minimum a primary and a secondary EMI relationship, with each agreement scoped to a defined payment product or geography. This does not require duplicating the full compliance burden; with the right structure, the secondary relationship can be a lighter-touch arrangement for overflow and continuity purposes.

If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Write to OBOLUS at info@oboluslaw.com to map your onboarding options.

What Does Client-Money Safeguarding Require in a Digital-Asset PSP Structure?

Client-money safeguarding is a regulated obligation that sits between the payment regime and the crypto-asset regime – and the intersection is often where compliance gaps appear. Under the applicable provisions of major payment frameworks, an EMI or payment institution holding funds on behalf of clients must safeguard those funds by segregating them from the institution's own funds and either placing them in a dedicated safeguarding account at a credit institution or covering them with an insurance policy or guarantee.

For a crypto operator running a combined fiat and digital-asset business, this creates a structural question that goes beyond the PSP agreement itself: which part of a customer's balance is subject to safeguarding regulation, and which part is held as crypto-asset custody? The answer depends on the activity: fiat received from a customer before it is converted into a digital asset is typically subject to the payment regime's safeguarding rules for the period it is held. Once converted and held as a digital asset, it falls under whichever custody regime applies – VARA, FSRA, MiCA, or the relevant national equivalent.

The PSP agreement must map this clearly. If the operator's agreement with its EMI covers only the fiat leg of a conversion transaction – which is the typical scope – the agreement should be explicit that the EMI's safeguarding obligation begins on receipt of fiat and terminates on transfer to the operator's settlement account. Any ambiguity about the scope of safeguarding creates liability for both parties: for the EMI, if it failed to segregate; for the operator, if it received funds that the EMI had already blended into its operating pool.

In a recent matter, a payments company operating an on/off-ramp in multiple markets had structured its EMI agreements without addressing the safeguarding handoff point for fiat held overnight pending conversion. When a processing partner raised a compliance query, it became unclear which entity held the safeguarding obligation for the balance. We advised on restructuring the contractual chain to make the handoff explicit, reducing both the operator's regulatory exposure and the EMI's reluctance to continue the relationship.

Which Structure Fits Which Operator Profile?

The right PSP and acquiring structure is not universal – it depends on the operator's activity type, licence status, geographic footprint and risk tolerance. The following matrix describes the principal decision branches we encounter in practice.

Profile A: EU-licensed CASP serving retail customers in multiple member states. This operator holds or is pursuing a CASP authorisation in a single EU member state and uses MiCA passporting to serve customers across the bloc. The appropriate PSP structure pairs an EU-authorised EMI (ideally in the same or an adjacent member state) as the primary counterparty, with contractual scope limited to the activity types covered by the CASP authorisation. The rolling reserve should be calibrated to the operator's chargeback profile for fiat-to-crypto conversions specifically. Timeline from structured onboarding application to live processing: varies by EMI, but well-prepared operators typically progress to a term sheet within a matter of weeks.

Profile B: VARA-licensed exchange seeking European fiat rails. This operator holds a VARA activity-based licence in Dubai and wants to process euro-denominated payments for European users. The core structuring challenge is that VARA is a Dubai-mainland regime and carries no formal EU recognition under MiCA. The operator requires either a separately licensed EU entity (which may need its own CASP authorisation for the relevant activities) or a carefully scoped EMI agreement that limits the European processing to activities that do not themselves trigger EU licensing obligations. The agreement must be drafted with explicit carve-outs reflecting this boundary. Allied counsel in the EU jurisdiction are required to opine on the licensing question.

Profile C: Early-stage operator with registration only, seeking a bridging PSP relationship. This operator holds an AML registration (for example, under the FCA's MLR in the UK or an equivalent in a lighter-touch regime) and needs fiat access while pursuing a full CASP or payment licence. The PSP market for this profile is narrower and the terms more conservative: expect higher reserve percentages, shorter initial contract terms and more intensive due diligence. The structuring priority here is to ensure the agreement does not contractually represent the operator as holding a licence it does not yet hold – a misrepresentation that would trigger immediate termination and potential regulatory referral.

Does a Well-Known Crypto Licence Solve the PSP Problem?

A common assumption among operators is that obtaining a licence from a well-regarded regulator – VARA, MAS, or the SFC – automatically opens the door to PSP and banking relationships. This is not how payment counterparties assess risk, and counsel should correct the assumption early.

A licence is a necessary condition in many PSP negotiations, not a sufficient one. The EMI or acquiring bank conducts its own risk assessment that looks past the licence to the underlying business: the customer mix, the transaction types, the geography of user origination and the operator's own AML compliance infrastructure. We have seen operators with strong licences in leading jurisdictions fail EMI onboarding because their customer due diligence documentation was insufficiently granular, or because their transaction monitoring was calibrated only to on-chain flows and not to the fiat-conversion activity the EMI would be processing.

The converse is also instructive. An operator with a lighter-touch registration in a smaller jurisdiction – the AIFC/AFSA framework in Kazakhstan, or the MFSA's VFA transitional regime in Malta – can succeed in EMI onboarding if it presents a compliance infrastructure that is materially stronger than its licensing category requires. PSPs are making a commercial and regulatory judgement, not simply verifying a licence number. The structuring argument must therefore address the full compliance picture, not just the headline licence.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts most often because the account holder's activity type, AML documentation or transaction profile falls outside the bank's own risk appetite – not necessarily because the company has done anything unlawful. Common triggers include insufficient KYC documentation on the operator's own customers, a mismatch between the declared business model and actual transaction flows, and the absence of a recognizable licence in the bank's home jurisdiction. Structural remedies include presenting a jurisdiction-appropriate compliance package, using an EMI intermediary and matching the contracting entity to the geographic scope of the activity.

How can a VASP onboard with an EMI?

A VASP can onboard with an EMI by presenting a structured compliance package that addresses the EMI's own regulatory obligations rather than simply asserting its crypto licence. This means providing AML/CFT policies tailored to the payment activities to be processed, evidence of Travel Rule compliance for the on-chain leg, a clear description of the customer base and transaction types, and – where required – a legal opinion on the operator's licensing status in the markets the EMI will be processing for. Entity structure matters: an EU-incorporated operating subsidiary typically achieves better terms than an offshore holding entity contracting directly.

What does client-money safeguarding require?

Under the applicable provisions of major payment frameworks, an EMI holding client funds must segregate those funds from its own and protect them either through a dedicated safeguarding account at a regulated credit institution or through an equivalent insurance or guarantee arrangement. For crypto operators, the key structuring question is where the safeguarding obligation begins and ends relative to the on-chain custody layer. PSP agreements should define the handoff point explicitly – typically the moment fiat is transferred to the operator's settlement account – to prevent ambiguity about which entity bears the obligation for overnight or in-transit balances.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence, payment and custody stack across operating layers before you commit – so that your fiat rails are built on durable legal foundations, not assumptions. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.

By Glen Sorensen, Disputes & Recovery Analyst – specialising in PSP agreement disputes, fiat-rail enforcement and cross-border recovery across common-law forums.

To pressure-test your PSP and acquiring structure before you commit, message OBOLUS via t.me/oboluslaw or write to info@oboluslaw.com.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours