Securing fiat rails (the bank accounts, payment service provider relationships and acquiring connections that let a digital-asset business move money) is the operational bottleneck that ends more builds than regulatory rejection does. A crypto exchange or token issuer that cannot settle fiat cannot trade. That is the loss a poorly drafted PSP or acquiring agreement makes real. This guide walks through every material step in the negotiation, identifies the regulated basis at each stage, flags the cross-border reality operators routinely underestimate, and marks the mistake that most commonly kills a deal.
Step 1: Understand What You Are Actually Buying
A PSP agreement (payment service provider agreement) and an acquiring agreement are distinct instruments with different regulatory footprints, and confusing them in negotiations signals inexperience to the counterpart. A PSP agreement governs the provision of payment initiation, account information or money-transmission services between a licensed payment institution and a merchant or business client. An acquiring agreement covers the acceptance of card-scheme transactions – Visa, Mastercard and their equivalents – and brings card-scheme rules directly into the contractual relationship. A digital-asset business may need both, or neither if it operates purely on-chain, but the starting point is clarity on which instrument solves which problem.
The regulatory basis matters immediately. Under MiCA and the underlying Payment Services Directive regime, the services a PSP is permitted to provide are enumerated. Your agreement must map precisely to those permitted services. Any activity outside the authorised scope creates regulatory exposure for the PSP – and that exposure migrates contractually to you through indemnity, termination and step-in provisions. In our practice, we have seen operators accept boilerplate agreements that granted the PSP termination rights so broad that a single regulatory inquiry – not a finding, an inquiry – was a termination event. That is not a drafting formality. It is a structural risk.
The cross-border note at this step: the PSP or acquirer is authorised in one jurisdiction; you operate in several. The agreement's governing law is the PSP's home jurisdiction. The services you need may not be permitted there for a VASP (virtual asset service provider). Identify the mismatch before you execute, not after.
Common mistake at Step 1: Accepting the PSP's standard "merchant services" agreement without checking whether the VASP carve-outs in its acceptable-use policy silently exclude your business model. Many standard templates include blanket restrictions on "cryptocurrency" or "digital assets" that neither party flags at negotiation.
Step 2: Conduct Pre-Negotiation Due Diligence on the Provider
Before you disclose your business model, verify that the provider's licence actually covers the services you need in every jurisdiction where you intend to use the rails. An EMI (electronic money institution) authorised under an EU regime can passport across EU/EEA member states for permitted payment services, but that passport does not extend to the UK post-Brexit, to the UAE, or to Singapore. A PSP operating on a single EU licence is structurally incapable of serving your UAE-incorporated entity through that same agreement without additional authorisation.
Check the provider's regulatory register entries directly – the FCA register, the relevant national competent authority under MiCA, or the MAS published licence list. Do not rely on the provider's marketing materials. In our cross-border practice, we have encountered providers whose passporting rights had lapsed or whose registration covered a narrower set of activities than their pitch deck described. An agreement built on that foundation will fail at the worst possible moment.
Also verify the card-scheme memberships if acquiring is in scope. Mastercard and Visa maintain publicly available lists of principal and associate members. If the acquirer's membership is suspended or under review, that surfaces in due diligence – not in the agreement.
Common mistake at Step 2: Relying on the provider's self-description of its regulatory perimeter. The five-minute check against the relevant regulator's public register is non-negotiable.
For a scoped review of your provider's regulatory standing before you negotiate, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your entity structure, user base and jurisdictional mix change the analysis materially. Map your options.
Step 3: How Should You Frame Your KYB Package for the Provider?
The way you present your business in the onboarding KYB (know-your-business) process shapes every subsequent negotiation position, including pricing, reserve levels and acceptable-use scope. Providers that are unfamiliar with digital-asset businesses apply the highest-risk classification by default. Your job is to reframe that classification with evidence before the underwriting file is assembled.
The KYB package for a VASP or crypto-adjacent business should include, at minimum: the full regulatory licence or registration from the relevant authority (VARA, AFSA, MAS, FCA or the applicable national competent authority under MiCA); the AML/CFT policy and the most recent AML audit or review; the corporate structure chart with all beneficial owners at the relevant threshold; an explanation of the business model in plain language with transaction-volume projections; and a sample of the on-chain analytics tool used for transaction monitoring. Operators we advise routinely underinvest in that last element. A provider's compliance team does not understand on-chain risk the way a crypto-native compliance officer does. The analytics report is the translation layer.
The cross-border note: if your structure involves an operating entity in one jurisdiction and a custody or treasury entity in another, the provider will ask about fund flows between them. Have that answer scripted and documented before onboarding begins. An inconsistent answer at KYB is treated as a red flag, not an oversight.
Common mistake at Step 3: Submitting a KYB package assembled for a different provider or a prior application without updating the transaction-volume projections. Stale figures that conflict with the live business create the impression of misrepresentation.
Step 4: What Commercial Terms Are Most Negotiable in a PSP Agreement?
The commercial terms in a PSP or acquiring agreement are more negotiable than most operators assume, particularly at the moment of initial onboarding when the provider is seeking to win the business. The key variables are the reserve structure, the settlement cycle, the chargeback-liability cap and the fee schedule.
A rolling reserve (a percentage of settlements held back by the provider as a risk buffer) is standard in digital-asset contexts. The negotiating question is the percentage, the holding period and the release mechanism. Providers initially propose reserves calibrated to their worst-case chargeback experience in the sector. If your business has demonstrable low chargeback rates – supported by data from a prior acquirer or from your card-scheme reporting – that data is the negotiating instrument. Present it early.
Settlement cycles matter acutely for a business that carries thin working capital. A T+3 settlement cycle means three days of float sits with the provider. In high-volume environments, that is material. Negotiate the cycle explicitly and link it to performance milestones – a shorter cycle unlocks if chargeback rates stay below a defined threshold for a defined period.
Fee schedules in standard templates are rarely the floor. MDR (merchant discount rate) for digital-asset merchants is higher than for low-risk retail because the provider's card-scheme cost is higher. But the components of the MDR – scheme fees, interchange, acquirer margin – are separable. Insist on an interchange-plus or cost-plus pricing model rather than a blended rate. Blended rates obscure the acquirer's margin and make it impossible to benchmark at renewal.
Common mistake at Step 4: Negotiating only on rate while ignoring the reserve and termination provisions. A favourable rate inside an agreement that lets the provider terminate on 30 days' notice without cause is not a good deal.
Step 5: Negotiate Termination and Suspension Provisions with Precision
The termination and suspension provisions in a PSP or acquiring agreement are the highest-risk clauses for a digital-asset business, and they receive the least attention in negotiations. A provider can effectively end your fiat rails by suspending settlement – holding funds without terminating the agreement – and the standard template gives them very broad discretion to do that.
The clauses to review and negotiate are: (a) the definition of a "regulatory event" or "compliance event" that triggers a suspension right; (b) the notice period before suspension takes effect; (c) the process for the operator to cure a perceived breach before suspension is enforced; (d) the maximum holding period for funds during suspension; and (e) the mechanism for releasing reserves after termination. In our practice, we have seen agreements where the provider could suspend settlement indefinitely pending resolution of a "regulatory inquiry" with no obligation to notify the operator of the nature of the inquiry. That is unacceptable drafting for a business that depends on those rails.
The cross-border note: if your business is subject to a regulatory process in one jurisdiction, that process may trigger suspension rights under agreements governed by a different jurisdiction's law. The definition of "regulatory event" must be scoped to findings, not to inquiries or investigations. The distinction is material.
Common mistake at Step 5: Accepting "regulatory event" definitions that include the commencement of any regulatory process. Narrow the definition to a final adverse finding by the relevant authority, with an appeal-period carve-out.
If a prior agreement was terminated or your settlement was suspended and you need to understand the structural cause, write to OBOLUS at info@oboluslaw.com. A second read of the agreement frequently surfaces the route back. Map your options.
Step 6: How Do Cross-Border Entity Structures Interact with PSP Agreements?
Most digital-asset businesses operate through a multi-entity structure: a licensed operating entity, a custody vehicle, a holding company and sometimes a treasury entity or fund. The PSP agreement is executed by one entity. The commercial reality is that several entities use the rails. That gap creates legal and regulatory exposure that the agreement must address explicitly.
The provider's acceptable-use policy will define who is a permitted user of the payment facility. If sub-entities or affiliates are not named, their use of the rails may constitute a breach. More practically, the settlement account must be held in the contracting entity's name. Routing settlements through an affiliate's account creates a funds-flow inconsistency that compliance teams and, eventually, regulators will flag.
Where a group structure requires multiple currencies or multiple settlement jurisdictions, each leg of the flow needs its own PSP or acquiring relationship, or an explicit multi-currency mandate in the principal agreement. Providers with a strong multi-currency settlement capability are fewer than the market suggests. The ones that serve digital-asset businesses across several settlement currencies are a smaller subset still.
The Travel Rule (the obligation, under FATF Recommendation 15 and implemented across major regimes, to pass originator and beneficiary information with a virtual-asset transfer) also intersects here. If your PSP or acquirer settles in fiat against on-chain receipts, the data-sharing obligations at the crypto/fiat boundary need to be resolved in the agreement or in an accompanying data-processing addendum.
Common mistake at Step 6: Executing the PSP agreement in the holding company's name when the operating licence is held by a subsidiary. The provider's KYB is done on the contracting entity. If a compliance query arises, the provider has no file on the entity actually conducting the regulated activity.
Step 7: Address Client-Money Safeguarding and Segregation Requirements
Client-money safeguarding is a regulated obligation, not a contractual preference. Under the payment services regimes in force across the major hubs – including the provisions applicable under the EU framework, the FCA rules and equivalent requirements in Singapore and Hong Kong – an EMI or payment institution holding funds on behalf of clients must safeguard those funds through segregation or insurance. The PSP agreement is the instrument through which that obligation is operationalised.
For a digital-asset business that holds client fiat pending conversion or settlement, the safeguarding structure must be agreed at the contract level. Which account holds the funds? Is it a designated safeguarding account with a credit institution? Is there a trust arrangement in place? What happens to the funds in the event of the provider's insolvency? These are not hypothetical questions. Several payment institutions have entered administration in recent years, and clients whose funds were not properly safeguarded experienced material recovery delays.
The cross-border note: safeguarding requirements vary by jurisdiction and by the type of funds in question. A provider authorised in the EU may apply EU safeguarding rules to EU-resident client funds but apply different standards to funds attributable to non-EU clients. If your client base is global, the agreement must specify which safeguarding standard applies to which pool.
Common mistake at Step 7: Treating the safeguarding clause as a regulatory box to tick rather than a substantive protection. Operators that do not require a named safeguarding account in the agreement have no contractual mechanism to enforce segregation if the provider's internal practice departs from it.
Step 8: Build the Renewal and Data Portability Position Before You Sign
The leverage a digital-asset business has in a PSP negotiation is highest before execution. After execution, the power shifts to the provider. The renewal and exit provisions must therefore be negotiated at inception, not when they become relevant.
The renewal clause should define the notice period for non-renewal, the process for renegotiating commercial terms at renewal, and whether the provider can introduce new acceptable-use restrictions during the renewal term. Many providers insert a clause permitting them to update acceptable-use policies on notice, with continued use of the services constituting acceptance. That clause is an asymmetric risk. Counter it with a requirement for written consent before any amendment that materially restricts the scope of permitted activities.
Data portability matters because switching providers requires presenting transaction history to the new provider's KYB and underwriting process. If the agreement does not grant you the right to a machine-readable export of your full transaction history on termination, you cannot migrate efficiently. That friction is deliberate on the provider's side. Negotiate the export right explicitly, with a defined format and a defined delivery window after termination.
Operators we advise regularly discover at the point of switching that their prior agreement had no data-export provision. The practical result is a gap in the transaction record that the new provider treats as a risk indicator. The cost of not negotiating this clause at inception is paid at the point of exit.
Common mistake at Step 8: Assuming that data portability is implied. It is not. Without an express provision, the provider has no contractual obligation to deliver your transaction history in a usable format.
In a recent banking onboarding matter, a payments business operating across three jurisdictions engaged OBOLUS before finalising its PSP agreement. The business had already received a draft that included a rolling reserve of a size that would have constrained its working capital, an open-ended "regulatory event" suspension right, and no data-export clause. We renegotiated all three points before execution, including a reserve step-down schedule tied to chargeback performance and an express obligation on the provider to deliver a full transaction export within a defined period after termination. The business launched on its intended timeline.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital-Asset Businesses – our full practice overview covering fiat rail strategy, EMI onboarding and licence interaction
- Fiat On/Off-Ramp Banking for Established Operators – practical guidance on building and protecting fiat access for operating businesses
- On-Chain Asset Tracing in Ireland – how Irish courts support digital-asset recovery and disclosure orders
FAQ
Why do banks close crypto company accounts?
Banks close digital-asset company accounts primarily because of de-risking – the decision to exit a category of client perceived as carrying high compliance cost relative to revenue. The proximate triggers are usually: a missing or lapsed regulatory licence, transaction-monitoring alerts that the business cannot explain with adequate documentation, or a change in the bank's internal risk appetite for VASP exposure. A business with a clear licence from a recognised authority, a documented AML programme and a well-presented KYB file is materially less likely to be de-banked than one that relies on informal relationships.
How can a VASP onboard with an EMI?
A VASP seeking EMI onboarding should prepare a KYB package that includes its regulatory licence or registration, an AML/CFT policy, a beneficial ownership chart, transaction-volume projections and a summary of the on-chain monitoring tools in use. EMIs authorised under an EU regime can passport payment services across EU/EEA member states, but that passport does not extend to the UK, UAE or Singapore. Matching the EMI's licence to your operational jurisdictions before onboarding avoids the most common structural failure at this stage.
What does client-money safeguarding require?
Client-money safeguarding under payment services regimes requires a licensed EMI or payment institution to hold client funds in a designated safeguarding account with a regulated credit institution, or to cover them through an equivalent insurance or guarantee arrangement. The purpose is to protect client funds in the event of the provider's insolvency. In practice, the PSP agreement must name the safeguarding structure explicitly. A contractual safeguarding obligation without a named account gives you limited recourse if the provider's internal practice departs from the stated arrangement.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before a client commits to a structure – and our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when banking relationships fail. Digital assets are the whole of our practice. Contact us at info@oboluslaw.com or via t.me/oboluslaw.
By Victor Olsen, Regulatory and Compliance Analyst – specialising in payment services regulation, EMI onboarding and the cross-border compliance requirements that govern digital-asset fiat rails.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.