French crypto regulation is tightening. A PSAN (prestataire de services sur actifs numériques – a digital-asset service provider registered or authorised under French law) that holds or transmits client funds faces a specific and unforgiving safeguarding regime administered by the AMF (Autorité des marchés financiers). Get it wrong and the consequences are concrete: enforcement action, suspended banking relationships and blocked fiat rails. This page maps the obligations, the inbound process and the cross-border considerations that every operator serving the French market needs to understand before committing to a structure.
The French PSAN regime and where safeguarding sits within it
The AMF administers the PSAN framework, which was introduced through legislation amending the French Monetary and Financial Code and which has evolved significantly as France prepares for full transition to MiCA (the EU's Markets in Crypto-Assets Regulation, supervised at European level by ESMA and national competent authorities). Under the current regime, registration is mandatory for certain activities – custody and buying/selling crypto against fiat are the most operationally significant – and an optional full authorisation track exists for operators seeking a higher trust signal with institutional counterparties. Safeguarding rules attach to the authorisation track and, in practice, to any PSAN that touches client money in a meaningful way.
The core obligation is straightforward in principle. Client funds must be held separately from the firm's own assets. In practice, that means either a segregated account at a credit institution or an arrangement with a payment institution or e-money institution that itself operates under PSD2-aligned safeguarding rules. The AMF expects the PSAN to document the arrangement, maintain it continuously and be able to demonstrate compliance on request. Operators we advise regularly underestimate how operational this requirement is: it is not a one-time box to check at authorisation; it is a live obligation.
The cross-border dimension sharpens the picture. A PSAN registered in France may well hold client funds through a non-French payment institution or an EMI domiciled elsewhere in the EU – an arrangement that is structurally permissible but that requires careful mapping of which safeguarding standard applies at each layer of the chain.
For a scoped assessment of how your current structure maps against the AMF's safeguarding expectations, write to the OBOLUS banking and payments team at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis.
What triggers the safeguarding obligation for a PSAN?
The safeguarding obligation activates whenever a PSAN is in a position to exercise control over client funds, even temporarily. Three operational scenarios drive the analysis. First, custody: a PSAN providing custody of digital assets on behalf of clients holds private keys, and the on-chain movement of associated fiat or stablecoins triggers safeguarding attention. Second, exchange: a PSAN operating a buy/sell or exchange service receives fiat from clients and is therefore holding client money between receipt and execution. Third, payment flow: a PSAN that sits in the settlement chain – collecting from buyers and disbursing to sellers – is functionally operating a payment service and must treat the float accordingly.
The distinction the AMF draws is between a PSAN that merely facilitates a peer-to-peer transaction and one that at any point holds an asset on a client's behalf. In our practice, the second category is far more common than operators initially assume. A matching engine that briefly holds fiat before settlement, a custodian that sweeps stablecoins into a pooled wallet, a lending platform that receives USDC as collateral – all of these create safeguarding exposure.
Stablecoins present a particular complexity. Tether (USDT) and Circle (USDC) hold contract-level freeze authority over their issued tokens and can act on court order or regulatory designation. A PSAN that holds client USDC in a pooled arrangement is exposed to issuer-level freeze risk as well as AMF-level safeguarding scrutiny – a dual-layer risk that demands a documented custody and safeguarding policy.
How does MiCA's arrival change the French rules?
MiCA changes the French regime materially, and the transition timetable matters for any operator currently under the PSAN framework. Under MiCA, the operative licence is the CASP authorisation (crypto-asset service provider), and a CASP authorised in one EU member state may passport across the EU/EEA – a significant structural improvement over the current position, where French PSAN registration does not carry the same passport right. France, like other member states, has been working through the transition mechanics: existing registered PSANs benefit from a transitional period, but the clock is running.
From a safeguarding perspective, MiCA introduces more granular requirements for CASPs that hold client funds or assets. The regulation distinguishes between custody and administration of crypto-assets (a regulated CASP activity) and the safeguarding of fiat funds pending settlement (which falls back on national payment-services law and, for EMTs, on MiCA's own e-money token provisions). The interaction between these layers is precisely where structural risk accumulates.
The practical consequence for an inbound operator is this: a structure built solely on a French PSAN registration will need to be re-evaluated against the MiCA CASP standard. Operators who have been deferring that analysis are now running out of runway. We have seen businesses in this position discover, late in the process, that their chosen entity structure and banking arrangement need significant restructuring to meet the new standard.
What is the inbound process for an operator seeking PSAN registration in France?
Registration – not the full authorisation track – has been the practical entry point for most inbound operators. The AMF process requires a dossier that covers corporate structure and beneficial ownership, an AML/CFT programme aligned with FATF Recommendation 15 (the FATF standard requiring virtual-asset service providers to implement risk-based AML controls), IT and cybersecurity documentation, and – critically for the purposes of this page – a clear description of the safeguarding arrangement for client funds.
The timeline from submission to decision varies by the quality of the dossier and by AMF workload. Qualitatively, operators with well-prepared submissions who are responsive to AMF information requests move faster than those who treat the registration as a formality. In our practice, the most common cause of delay is an incomplete or internally inconsistent safeguarding description – either the operator has not yet secured its banking or EMI arrangement, or the arrangement it has secured does not clearly map to the AMF's expectations.
The sequence we recommend to clients is: finalise the safeguarding structure before filing, not after. That means identifying the credit institution or payment institution that will hold segregated client funds, obtaining written confirmation of the arrangement and building the AML/CFT programme around the actual operational flow. A dossier that describes a notional future arrangement rather than a signed present one will generate AMF queries and delay.
Full authorisation – the optional higher track – requires additional governance and capital documentation. It is worth considering for operators who intend to serve institutional counterparties or who are building toward a MiCA CASP authorisation, since the discipline of the authorisation process provides a structural baseline for the transition.
Cross-border banking and EMI onboarding: the practical bottleneck
The safeguarding obligation is only as strong as the banking or EMI arrangement that underpins it. This is where French PSAN operators routinely encounter the hardest practical constraint. French credit institutions are cautious in onboarding crypto businesses. That caution is not arbitrary: it reflects the AML/CFT risk appetite of the individual institution and, in some cases, correspondent-banking pressure from US dollar clearing banks that remain uncomfortable with crypto counterparties.
The result is that many French PSANs – and many inbound operators seeking French registration – need to source their safeguarding account from an EMI or payment institution domiciled elsewhere in the EU. That is structurally permissible. A Lithuanian or Maltese EMI, operating under the Payment Services Directive and its own national AML regime, can hold segregated client funds for a French PSAN. But the AMF will want to understand the arrangement: the EMI's authorisation status, its safeguarding methodology (segregation or insurance/guarantee) and how client funds can be identified and returned in an insolvency.
In our cross-border practice, the EMI onboarding process is often the longest-lead item in a France market-entry project. EMIs conduct their own due diligence on PSAN clients – sometimes more granular than the AMF's own process – and they are entitled to decline or to impose conditions. Operators who approach the EMI relationship late, or who have not prepared a complete compliance and business-model pack, typically face delays measured in months rather than weeks.
The cross-border angle extends to tax. A French PSAN holding client funds through a non-French EMI needs to consider whether the flow of funds creates a taxable presence in the EMI's jurisdiction and whether the intercompany arrangement is priced at arm's length. These are not afterthoughts; they are structural design questions that should be resolved before the first account is opened.
If your EMI onboarding has stalled or a banking relationship has been declined, a structured second review can surface the cause and the route forward. Write to us at info@oboluslaw.com. If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back.
AML, the Travel Rule and FATF alignment in the French context
France is an active FATF member, and the AMF's AML/CFT expectations for PSANs reflect FATF Recommendation 15 closely. The Travel Rule (the obligation to pass originator and beneficiary data alongside a virtual-asset transfer) applies to PSANs that transmit assets on behalf of clients. Compliance requires a technical solution – a messaging protocol capable of transmitting the required data to the receiving VASP – and a policy framework that addresses how to handle transfers to or from unhosted wallets.
The Travel Rule data threshold and its de-minimis carve-out are set at the national implementation level and are subject to change as MiCA transition progresses; operators should consult current legislation rather than rely on any fixed figure stated in secondary sources. What is stable is the structural obligation: PSANs must collect, transmit and retain the data, and must have a risk-based policy for transfers where the counterpart VASP is not identifiable.
The interaction between Travel Rule compliance and safeguarding is closer than it appears. A PSAN that cannot identify the beneficial owner of incoming funds faces a safeguarding dilemma: it cannot safely commingle those funds with identified client balances, and it may be required to reject the transfer. Building the AML programme and the safeguarding policy as a single integrated framework – rather than two separate compliance exercises – is the approach that holds up under AMF scrutiny.
A matter in practice: restructuring a safeguarding arrangement under AMF scrutiny
In a recent engagement, an exchange operator registered as a PSAN had been holding client fiat through a pooled account at a domestic credit institution that subsequently withdrew crypto-business services. The operator faced a gap between its existing AMF documentation – which named the institution as the safeguarding counterpart – and its actual position. We mapped the available EMI options across three EU jurisdictions, supported the preparation of a revised safeguarding description for the AMF file and coordinated the onboarding process with the replacement institution. The revised arrangement was documented and submitted within the AMF's notification window, and the operator maintained continuous registration status without a gap. The matter illustrated how quickly a banking change can become a regulatory compliance event in the PSAN context.
Decision point: which operators need a France-specific safeguarding structure?
Not every operator serving French users needs a French PSAN registration. The threshold question is whether the activity, the client base and the asset types bring the operator within the French regulatory perimeter – or within MiCA's scope, which will increasingly be the operative question.
Profile A – the pure crypto-to-crypto exchange with no fiat on/off ramp – sits in a different regulatory position than Profile B – the exchange that collects euros from French retail clients, converts to BTC and holds a euro float pending settlement. Profile B is the clearest safeguarding obligation case. Profile A needs to assess whether its activity constitutes custody or exchange under the AMF's interpretation, and whether MiCA's asset categories change that analysis.
Profile C – the institutional OTC desk that deals only with professional counterparties and settles same-day without retaining a float – presents a different risk profile again. The safeguarding obligation may be lighter, but the AML/KYC and Travel Rule obligations remain, and institutional counterparties increasingly require documented evidence of regulatory status before they will transact.
A common assumption is that a single offshore licence – a BVI VASP registration or a Cayman CIMA acknowledgment, for example – is sufficient to serve clients globally, including in France. It is not. French and EU law applies to services offered to French residents regardless of where the provider is incorporated. The AMF and, increasingly, ESMA have made clear that jurisdictional arbitrage does not neutralise the obligation. An operator that has structured on the assumption that offshore status provides a French market entry is carrying a material regulatory risk that the right structure should address.
We map the licence, banking and safeguarding stack across operating, custody and payment layers before you commit. To pressure-test your structure, message us via t.me/oboluslaw.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital-Asset Businesses – structuring fiat rails, safeguarding and payment licences for crypto operators
- EMI Onboarding for VASPs in Georgia – an alternative EU-adjacent banking route for operators seeking payment-institution access
- VASP Business Risk Assessment in Australia (AUSTRAC) – AML/CTF risk assessment requirements for digital-asset businesses under the AUSTRAC regime
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because of AML/CFT risk appetite and correspondent-banking pressure. Many domestic credit institutions face restrictions from their own dollar-clearing counterparts, which remain cautious about crypto-related flows. A PSAN or CASP that has not documented its compliance programme, its client onboarding standards and its transaction-monitoring methodology in terms the bank's compliance team can evaluate is a difficult client to retain. The solution is not to find a more accommodating bank; it is to present the business in a form that meets institutional due-diligence expectations.
How can a VASP onboard with an EMI?
A VASP (virtual asset service provider) onboards with an EMI (e-money institution) by satisfying the EMI's own compliance review, which typically covers corporate structure, beneficial ownership, the business model, AML/KYC policies, a sample client file and regulatory status. EMIs authorised under the Payment Services Directive conduct this review under their own AML obligations and may decline clients they consider high-risk. Preparation matters significantly: operators who submit a complete, coherent compliance pack move through EMI onboarding materially faster than those who engage without one.
What does client-money safeguarding require?
Client-money safeguarding requires that funds received from clients be held separately from the operator's own funds at all times. In the French PSAN and EU payment-services context, this means a segregated account at a credit institution, EMI or payment institution, with documentation evidencing the arrangement and the ability to identify and return client balances in an insolvency. The precise methodology – whether segregation, insurance or a guarantee – depends on the applicable regime and the operator's activity type. What is constant is the obligation to have the arrangement in place, documented and current before holding any client funds.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence stack across operating, custody and payment layers before you commit. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in PSAN/CASP registration, AML/CFT programme design and cross-border licensing strategy for digital-asset operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.