EST · MMXXVI
Home/Insights/Tech/PSP and acquiring agreement: What Recent Enforcement Tells Operators
Banking, Payments & EMI Onboarding

PSP and acquiring agreement: What Recent Enforcement Tells Operators

Psp and acquiring agreement: What Recent Enforcement Tells Operators. Cross-border digital-asset legal counsel for business – licensing, disputes and structurin

Payment rails fail before licences do. A digital-asset operator discovers this not in a compliance review but at the moment a PSP (payment service provider) terminates an acquiring agreement and fiat settlement stops – sometimes overnight, sometimes mid-settlement cycle. That moment converts a regulatory abstraction into a live commercial crisis: customer onboarding freezes, treasury cannot move, and the business has hours to respond. The legal question the moment raises is not simply "do we have a licence?" It is: which obligations inside the acquiring agreement created the termination right, were those obligations driven by the underlying regulatory regime, and what structural decisions – made months earlier – allowed that exposure to exist?

Recent enforcement patterns across the major payment hubs tell a consistent story. Regulators and acquiring banks are now treating the digital-asset operator's own regulatory status as a direct input into PSP risk appetite, not merely background context. A VASP (virtual asset service provider) that holds the right licence in its home jurisdiction but lacks a credible cross-border compliance posture – covering fiat rails (the bank and payment infrastructure through which crypto businesses move money), EMI onboarding, and customer-fund safeguarding – will find that acquiring agreements contain termination triggers the operator never spotted in due diligence. This analysis maps those triggers, the contrasting positions operators and PSPs take when enforcement arises, and the structural choices that determine which side of the outcome you land on.

The sections below move from the regulatory context through the anatomy of a PSP acquiring agreement, the enforcement signals visible across the FCA, MAS, ESMA and VARA environments, the cross-border conflict points, and the decision matrix that distinguishes the operators who keep their rails from those who lose them.

The Regulatory Backdrop: Why PSPs Are the New Compliance Frontier

Acquiring banks and payment service providers have become a secondary enforcement layer for digital-asset regulation. The FCA's AML registration requirement, MiCA's CASP authorisation regime under ESMA, MAS's Payment Services Act licensing tracks, and VARA's activity-based licence structure in Dubai all share a common logic: if the operator cannot demonstrate a clean regulatory status to its payment counterparty, the payment counterparty faces its own supervisory risk for servicing that client. The result is that PSPs and acquiring banks now conduct independent compliance reviews – often more granular than the operator's own regulatory examination – before and during an account relationship.

The FCA's financial-promotion rules for crypto assets extended this dynamic materially. Once a digital-asset business marketing to UK persons had to comply with those rules, the FCA's registered or authorised status of that business became visible – or conspicuously absent – to any payment provider holding a UK e-money institution licence. A UK EMI servicing an unregistered crypto business faces direct exposure. That exposure is now priced into onboarding policies across the major UK acquiring banks and EMIs.

In our cross-border practice, we see the same pattern applied by EU-based payment institutions under MiCA's transitional provisions. A business that was operating under a legacy VASP registration in a member state and has not progressed its CASP authorisation application will find that EU payment counterparties begin flagging the account for enhanced due diligence – and in several cases we have tracked, close it before the authorisation timeline resolves. The PSP cannot wait for the regulator's timetable.

The enforcement signal is not always a formal sanction. It is the quieter administrative action: the SAR filing that triggers an account suspension, the onboarding questionnaire that the operator cannot answer cleanly, the correspondent bank's de-risking policy that removes the EMI's appetite for crypto clients entirely. Operators who focus only on headline regulatory actions miss this capillary-level pressure entirely.

Anatomy of a PSP Acquiring Agreement: Where the Termination Triggers Live

A PSP acquiring agreement terminates on a narrower set of triggers than operators typically read at signing – and those triggers are almost always in the representations, the acceptable-use policy, and the change-in-circumstances clause, not in the principal operational provisions. Understanding those three locations is the starting point for any legal assessment of termination risk.

The representations and warranties in a standard acquiring agreement require the merchant or business to confirm, at the point of onboarding and on a continuing basis, that it holds all required licences and registrations to operate its business in the jurisdictions it serves. For a digital-asset operator, this representation is not merely a formality. It is the mechanism by which the PSP imports the operator's entire regulatory status into the agreement. Any change in that status – a licence suspension, a failure to obtain MiCA CASP authorisation before a transitional deadline, a VARA licence application rejection – automatically triggers a breach. The PSP's termination right follows immediately, without notice in many agreements, or on short notice in the better-drafted ones.

The acceptable-use policy sets the permitted business activities. Where the acquiring agreement was entered before the operator expanded into a new product line – staking services, lending, tokenised securities trading – the new activity may fall outside the original permitted scope. Operators routinely fail to notify their PSP of product expansions. In our advisory work, we have seen this omission treated by the PSP as a material misrepresentation, not merely an administrative oversight. The legal difference matters: a misrepresentation typically gives the PSP a right to unwind the agreement from inception, not merely to terminate prospectively.

The change-in-circumstances clause is the broadest and most underestimated risk. It gives the PSP a right to terminate if the operator's regulatory environment changes in a way the PSP determines materially increases its own risk. As MiCA obligations have matured, several EU-based EMIs have activated this clause against crypto business clients who remained in a holding pattern during the transitional period. From the EMI's perspective, the clause was lawfully exercised. From the operator's perspective, the termination arrived without a specific breach to point to and without a clear remediation path.

Strong PSP-side drafting — the kind operators rarely push back on — will also include a right to withhold settlement during the notice period. For a crypto exchange processing meaningful daily volume, a 14-day withholding of settlement funds is a liquidity event, not a procedural inconvenience. The practical enforcement consequence of a PSP termination is often felt in the settlement reserve, not in the termination notice itself.

To discuss the termination provisions in your current acquiring agreement and identify the structural exposures before they activate, contact OBOLUS at info@oboluslaw.com. The process above describes the standard risk profile. Your specific agreement, entity structure, and cross-border user base will change the analysis materially. Map your options with our team before a notice arrives.

What Recent Enforcement Patterns Tell Operators About PSP Risk

The clearest signal from recent enforcement is that regulatory action against a PSP serving digital-asset clients is now a material precedent that every other PSP in that jurisdiction reads immediately. When a regulator takes action against an EMI for inadequate AML controls over its crypto-business client base, the market response is not confined to the sanctioned institution. It propagates through the sector within weeks as a de-risking trigger. Operators who lose their PSP relationship in the wake of a sector-wide enforcement action often find the market has contracted simultaneously – not because of anything specific to their business, but because the risk category they occupy has been re-priced.

Under the MAS Payment Services Act regime, the tiered licence structure – distinguishing standard payment institutions from major payment institutions by volume thresholds – creates a documented compliance expectation that cascades to the PSP's business clients. A digital-asset operator whose own MAS licence category does not match its actual transaction volumes is in breach of the regime independently. That breach becomes visible to every downstream payment counterparty in Singapore when the MAS publishes its supervision notices. In our practice, we advise operators entering the Singapore market to calibrate their licence tier to their realistic volume projections, not their day-one volumes, precisely to avoid this gap emerging as the business scales.

Under VARA's activity-based framework in Dubai, the position is structurally different. VARA issues licences by activity rather than by entity type. An operator that holds an exchange licence but has expanded into custody or lending without a corresponding VARA licence is operating those activities without permission. The acquiring bank in the UAE – typically a bank subject to the Central Bank of the UAE's own guidelines on crypto-business clients – will typically detect this gap during periodic due diligence. VARA's rulebooks make the activity scope of each licence explicit, which means the gap between what the operator is doing and what the licence permits is documentable and visible to any diligent counterparty.

The FCA environment presents a different enforcement vector. The FCA's own registered population of crypto businesses has historically been small relative to the number of businesses marketing to UK persons. Where a business is not FCA-registered and is nonetheless accessing UK payment infrastructure, the FCA's financial-promotion regime creates direct exposure for the PSP processing the business's transactions. Recent FCA activity in this space has reinforced the signal that UK acquiring banks and EMIs face supervisory consequences for maintaining relationships with non-compliant crypto businesses. The practical result is an elevated level of periodic re-underwriting that operators with legacy relationships did not experience in earlier years.

The Cross-Border Conflict Problem: When Regimes Do Not Align

For most digital-asset operators, the entity holding the licence and the entities that actually hold user funds, process payments, and generate revenue are in different jurisdictions. This structural reality is the root cause of most PSP termination events that come across our desk – not a specific regulatory breach, but the accumulating misalignment between where the business is licensed, where its banking relationships sit, where its users are, and where its obligations run.

A common configuration: a CASP authorisation being processed in an EU member state, the treasury entity in the BVI or Cayman Islands, the payment processing running through a Lithuanian or Maltese EMI, and users across multiple EU and non-EU jurisdictions. Each layer of this structure has its own regulatory logic. The MFSA's VFA transitional framework in Malta, the Bank of Lithuania's supervision of VASP registrants, the BVI FSC's VASP Act regime, and the CIMA framework in Cayman each impose different obligations on the entities they supervise. The EMI in the middle of this structure – the one actually moving fiat – is looking at the entire picture and asking whether the aggregate structure is compliant with its own obligations.

The answer is rarely cleanly yes or no. It is a judgment about whether the risks of continuing the relationship, in light of what the EMI can verify, are within its own risk appetite. Where the judgment goes negative, the operator receives a termination notice that references the acquiring agreement's change-in-circumstances clause or a broad risk-policy provision. There is no specific breach to remediate. The operator's lawyers can dispute the contractual termination right – and in some cases that challenge has commercial leverage – but the underlying structural misalignment remains.

In our cross-border practice, we address this by mapping the regulatory obligations across all layers of the structure before the EMI or PSP relationship is established. The goal is not to find the single licence that covers the whole business – that licence does not exist. The goal is to ensure that each entity in the structure holds the permissions it needs for the activities it performs, that the AML posture is consistent and demonstrable across jurisdictions, and that the payment counterparty can verify compliance without having to make inferential leaps that increase its own risk perception.

A common assumption in the market is that a single offshore licence is sufficient to serve clients globally. It is not. A VASP registration in the BVI, for example, satisfies the BVI FSC's requirements for a BVI-registered entity. It does not constitute authorisation to offer services to EU persons under MiCA, to UK persons under the FCA regime, or to Singapore residents under the Payment Services Act. Each of those jurisdictions asserts regulatory reach over activities directed at persons within its borders, independent of where the operator is incorporated. A PSP with compliance obligations in those jurisdictions cannot treat an offshore registration as a substitute for the applicable local authorisation. This is the structural misconception that underlies a significant proportion of the PSP termination events we see.

Contrasting Positions: How PSPs and Operators Read the Same Agreement Differently

When a PSP terminates an acquiring agreement with a digital-asset business, the two sides rarely agree on what triggered the termination – and the legal argument turns on that disagreement. Understanding both positions is necessary to assess the remediation options and the litigation risk.

The PSP's position is typically that the agreement gave it a broad contractual discretion to manage its own regulatory risk, that the operator's representations about its licensed status were either inaccurate at the time of onboarding or have since become inaccurate, and that the change-in-circumstances clause was validly activated by a change in the regulatory environment that materially increased the PSP's own compliance exposure. From the PSP's perspective, the termination was a risk management decision made within the contractual terms, not a sanction and not a statement that the operator was in breach of regulation.

The operator's position is typically that its licence was valid at all material times, that any regulatory change was prospective and not yet determinative, that the PSP's internal risk reclassification does not constitute a "change in circumstances" within the contractual meaning of that phrase, and that the settlement withholding caused measurable loss that the operator is entitled to recover. Operators with leverage in this argument are those whose acquiring agreement was drafted with defined termination criteria – not a blanket discretion – and whose own compliance documentation was demonstrably current at the time of termination.

In practice, the asymmetry of the positions reflects the asymmetry of the relationship. PSPs hold the settlement reserve and control the payment infrastructure. The operator's leverage is its ability to demonstrate that the termination was not contractually justified and to seek either reinstatement or damages. We have seen both outcomes in commercial negotiation – reinstatement where the compliance gap was demonstrably closed, and a negotiated settlement of the withheld reserve where reinstatement was not commercially viable. The litigation path is available but rarely the most efficient resolution in the timeframe that matters to a live business.

The operators who are in the stronger position in this negotiation are those who made three structural decisions at the outset: they negotiated defined termination criteria rather than accepting boilerplate discretionary language; they maintained a continuous compliance documentation package that they could produce within 24 hours of a notice; and they held relationships with more than one payment counterparty so that the termination of one relationship did not sever all fiat rails simultaneously.

Micro-Matter: The Settlement Freeze

In a recent matter, a digital-asset exchange operating across multiple EU jurisdictions received a termination notice from its primary EMI shortly after the MiCA transitional deadline passed without the operator having filed a CASP authorisation application. The EMI cited its standard change-in-circumstances provision and withheld a seven-figure settlement balance pending its own risk assessment. We were engaged within 48 hours of the notice. Our immediate work covered three tracks: a contractual analysis of whether the EMI's termination right had been validly exercised under the specific agreement language, a regulatory review confirming that the operator's existing national VASP registration remained valid for a defined period under the applicable MiCA transitional rule, and a commercial negotiation with the EMI to release the settlement balance against a documented compliance timeline. The balance was released within three weeks. The operator filed its CASP authorisation application and retained the EMI relationship on revised terms. The outcome was possible because the regulatory position was defensible and the documentation was retrievable. Where either of those conditions is absent, the resolution takes considerably longer.

Client-Money Safeguarding and the PSP Interface

Safeguarding obligations – the requirement to hold client funds separately from the operator's own funds, typically in a designated account with a qualifying institution – sit at the intersection of the operator's regulatory obligations and the PSP's onboarding criteria. A PSP or EMI that holds designated safeguarding accounts for a digital-asset operator bears direct regulatory responsibility for those accounts. That direct responsibility is one of the reasons EMIs in the EU and UK are more cautious about crypto business clients than the headline regulatory requirements alone would predict.

Under MiCA's CASP regime, operators providing custody or safeguarding services face explicit regulatory obligations on client asset segregation. The EMI or custodian holding the fiat side of the safeguarding structure must be satisfied that the operator's own regime-level obligations are met before accepting the designation. Where the operator is in a transitional status – not yet CASP-authorised but not in breach – the EMI has to make a judgment about whether holding a safeguarding account for that client creates its own exposure. Several EU-licensed EMIs we deal with have adopted a conservative position: no new designated safeguarding accounts for crypto operators until CASP authorisation is confirmed. The practical consequence is that operators in the transitional period face an inability to onboard new payment partners at the precise moment they most need a diversified payment stack.

The structural answer to this problem is to establish safeguarding arrangements before the transitional deadline pressure arrives, while the EMI's risk appetite is based on the operator's existing valid registration. Waiting until the CASP authorisation process is advanced – but not yet concluded – is the worst timing. The EMI's risk assessment has been updated; the operator's licence status is still uncertain. In our advisory practice, we consistently recommend front-loading the payment-layer onboarding work alongside the initial licence application, not as a subsequent step.

The ADGM and FSRA framework in Abu Dhabi takes a similar approach to client asset safeguarding, with the FSRA's recognised virtual asset regime setting expectations about segregation and the operator's FSRA authorisation status functioning as a direct input into the banking relationship. Operators structured through ADGM tell us consistently that maintaining a demonstrably clean FSRA status is the single most effective lever for retaining correspondent banking relationships in the region.

Decision Matrix: Which Operator Profile Faces Which Risk

Not all digital-asset operators face the same PSP risk profile. The acquiring agreement exposure varies materially by business model, jurisdictional footprint, and compliance maturity. The following profiles capture the four configurations we see most frequently, with the corresponding risk exposure and the structural response each profile requires.

Profile A – the single-jurisdiction exchange with one PSP: This operator holds a valid licence in one hub jurisdiction, processes fiat through a single EMI, and serves users primarily in that jurisdiction. The risk here is concentration. A single termination event closes all fiat rails simultaneously. The structural response is diversification – a second payment relationship with a different EMI, ideally in a different regulatory jurisdiction, established before any compliance pressure emerges. The timeline for onboarding a second EMI relationship from scratch is typically a matter of months; in a termination crisis it may be unavailable entirely. Profile A operators routinely underestimate this timeline.

Profile B – the multi-jurisdiction operator with a holding structure: This operator has entities in multiple jurisdictions, each with different licensing statuses, all routing fiat through a single EMI that is the most convenient. The PSP risk here is structural misalignment, as described in the cross-border section above. The key risk event is the EMI conducting a periodic group-level due diligence review and finding that the aggregate compliance posture is less than the sum of its parts. The structural response is a compliance audit across all entities before the EMI conducts its own, with a clear ownership map, transaction-flow documentation, and a jurisdiction-by-jurisdiction licence status summary ready to produce on request.

Profile C – the operator in MiCA transition: This operator is operating under a legacy EU VASP registration and has filed or is preparing a CASP authorisation application. The PSP risk is the transitional gap: the EMI's risk appetite has already shifted to post-MiCA standards, but the operator's formal status has not. The structural response requires active communication with the EMI about the application timeline, a documented compliance roadmap, and where possible, a contractual amendment to the acquiring agreement that acknowledges the transitional status and defers the change-in-circumstances trigger until a defined authorisation deadline.

Profile D – the expansion-stage operator adding products: This operator began as a spot exchange or wallet provider and is adding staking, lending, or tokenised-asset products. Each new product line potentially requires a new or amended licence under the applicable regime – VARA's activity-based structure in Dubai, MiCA's specific treatment of different CASP activities, the SFC's VASP licensing in Hong Kong for platforms offering trading of virtual assets. The PSP risk is that the acceptable-use policy in the existing acquiring agreement does not cover the new activity, and the operator has not notified the PSP of the expansion. The structural response is a product-launch checklist that triggers a PSP review notification alongside the regulatory application, before the product goes live.

If a prior application stalled, an account was closed, or a termination notice arrived without a clear regulatory basis, a second read of the structure can surface the specific gap and the route back. Write to OBOLUS at info@oboluslaw.com or message via t.me/oboluslaw. Map your options before the settlement reserve becomes the negotiating lever.

EMI Onboarding: What Compliance Teams Actually Check

EMI onboarding for a digital-asset business is more intensive than standard corporate account opening, and the gap between what operators prepare and what EMI compliance teams actually require is a consistent source of delay and rejection. Understanding the review criteria from the EMI's perspective – not just the operator's documentation list – materially improves onboarding success rates and reduces the time to live payment rails.

At the core of an EMI's compliance review of a digital-asset client is a four-part assessment. First, the operator's own regulatory status: the licence held, the scope of permitted activities, the jurisdiction of supervision, and the alignment between the licence scope and the actual business activity. Second, the AML/CFT programme: the Travel Rule (the obligation to pass originator and beneficiary data with a transfer), the transaction monitoring system, the sanctions screening coverage, and the MLRO's qualifications and independence. Third, the client base: the geographic distribution of the operator's own clients, the KYC standards applied at onboarding, and the presence of high-risk jurisdictions in the transaction flow. Fourth, the beneficial ownership and control structure: who ultimately controls the operator, whether there are shell-holding layers that obscure the UBO, and whether any beneficial owner appears on relevant sanctions lists.

Operators who present a clean, pre-packaged compliance dossier covering all four areas from day one of the onboarding process reduce the EMI's review timeline substantially. Those who provide the minimum and respond reactively to information requests extend the process and create doubt about the underlying compliance posture. The EMI's compliance team is not simply collecting documents. It is forming a judgment about whether the operator runs its compliance function with the same seriousness the EMI runs its own. The documentation package is evidence of that judgment, not a box-ticking exercise.

The FATF Recommendations, including Recommendation 15 covering virtual assets, set the baseline expectation for both sides of this review. EMIs subject to the relevant national AML regime – whether under the EU's AML directives, the FCA's MLR framework, or MAS's regulatory expectations – are required to apply those standards to their business clients. Operators who can demonstrate FATF-aligned controls, articulated clearly and evidenced by policy documents and testing records, are materially easier for an EMI to onboard and materially harder for an EMI to justify closing.

Objection Handler: Why the "Offshore Licence Is Enough" Assumption Fails in Practice

A common assumption in early-stage digital-asset businesses is that obtaining a VASP licence in a cost-effective offshore jurisdiction – BVI, Cayman, or a similar common-law jurisdiction with a light-touch initial regime – is sufficient to operate globally and to satisfy the requirements of international payment counterparties. This assumption fails for three independent reasons, each of which produces a distinct practical consequence.

The first failure is jurisdictional reach. The BVI FSC's VASP Act applies to entities incorporated in the BVI. It does not authorise the offering of services to EU persons, UK persons, Singapore residents, or users in other jurisdictions that assert regulatory reach over activity directed at their residents. An operator with a BVI VASP registration directing marketing at EU persons is operating in the EU without CASP authorisation under MiCA. The BVI licence is irrelevant to that analysis.

The second failure is PSP acceptance. EMIs and acquiring banks in the EU, UK, Singapore and the UAE are subject to their own regulatory obligations in those jurisdictions. An EU-licensed EMI servicing a crypto operator that holds only a BVI registration and is actively marketing to EU persons faces the EMI's own MiCA-related compliance exposure. The EMI's compliance team will identify the gap and either decline to onboard or terminate the relationship after a periodic review surfaces the issue. The offshore licence does not resolve the EMI's problem; it creates it.

The third failure is correspondent banking. Correspondent banking relationships for EMIs servicing crypto businesses have contracted significantly over recent years as major correspondent banks have applied enterprise-wide de-risking policies to the sector. An EMI that cannot demonstrate to its correspondent that its crypto business clients hold the relevant authorisations in the jurisdictions they serve will find that correspondent banking access is contingent on that demonstration. An operator whose only licence is an offshore registration is the client that creates that problem for the EMI.

Operators we advise routinely come to us after having onboarded through an offshore registration and discovered – typically when the first PSP termination event occurs – that the structure was not built for the markets they actually serve. The remediation work is more expensive and more disruptive than the initial structuring would have been. We map the full licence, banking, and compliance stack before the business goes live precisely to avoid this sequence.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily because of their own regulatory obligations: AML/CFT compliance, correspondent banking de-risking policies, and the cost of enhanced due diligence for a sector with elevated transaction-monitoring requirements. A crypto operator that cannot demonstrate a compliant AML programme, a clean licence status in the jurisdictions it serves, and a transparent beneficial-ownership structure presents a risk-cost profile that many banks, particularly those with large correspondent banking networks, are unwilling to absorb. The closure is usually a risk management decision, not a finding of wrongdoing by the operator.

How can a VASP onboard with an EMI?

A VASP can onboard with an EMI by preparing a structured compliance dossier covering four areas: its licence status and permitted activity scope across all jurisdictions it operates in; its AML/CFT programme including Travel Rule compliance, transaction monitoring, and sanctions screening; its customer base profile including geographic distribution and KYC standards; and its beneficial ownership structure with full UBO disclosure. Presenting this package proactively – rather than responding reactively to information requests – reduces the EMI's review time and signals the compliance maturity the EMI's own supervisors require it to demonstrate.

What does client-money safeguarding require?

Client-money safeguarding requires a digital-asset operator to hold client fiat funds separately from its own operating funds, typically in a designated account at a qualifying institution such as a licensed bank or credit institution. Under regimes such as MiCA and the FCA's regulatory framework, the safeguarding obligation is a condition of the licence itself. The qualifying institution holding the safeguarded funds must be satisfied with the operator's own regulatory status before accepting the designated account. Operators in a transitional licensing status often find that establishing new safeguarding arrangements is temporarily unavailable until their authorisation is confirmed.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and when payment rails fail, we work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications. To discuss your situation, contact info@oboluslaw.com.

By Roman Levitt, Technology & DeFi Counsel – specialising in PSP agreement analysis, payment-licence structuring, and the regulatory interface between digital-asset operators and fiat-rail infrastructure across multi-jurisdictional builds.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours