Operating a digital-asset business in France without the correct payment-services authorisation is a live enforcement risk. The Autorité des marchés financiers (AMF) and the Autorité de contrôle prudentiel et de résolution (ACPR) together govern the twin tracks a crypto operator must secure: the PSAN (Prestataire de Services sur Actifs Numériques) registration with the AMF for digital-asset activities, and a payment-services or acquiring agreement with a licensed PSP (payment service provider) or EMI (electronic money institution) to move fiat in and out of the platform. Getting one without the other leaves the business legally exposed and commercially stranded. This page maps both tracks, the sequence in which they interact, and the cross-border considerations that most inbound operators underestimate.
The Regulatory Perimeter in France
France operates a two-regulator structure for digital-asset businesses: the AMF registers and supervises PSAN-category activities, while the ACPR supervises payment institutions and EMIs under the EU Payment Services Directive transposition. A crypto exchange, custody provider or broker typically requires both a PSAN registration and access to a licensed payment channel. Neither replaces the other.
The PSAN regime covers a defined list of activities – custody of digital assets, trading on own account, operation of a trading platform, reception and transmission of orders, portfolio management and advice. Each activity category triggers a separate registration obligation. An operator running an exchange and offering custody is not covered by a single generic registration; each activity must be declared.
The ACPR sits alongside the AMF on the fiat side. Payment initiation, account information, card acquiring, and the issuance of electronic money each require a separate authorisation under ACPR supervision. A PSAN registration does not confer payment-institution status. Conversely, holding an EMI licence from an ACPR-supervised entity, or onboarding with one, does not satisfy the AMF's PSAN requirement. French regulators treat these as parallel obligations.
Under MiCA, which applies across the EU, France's PSAN regime is in a transition period. ESMA and national competent authorities are coordinating the shift from national VASP regimes to the unified CASP (Crypto-Asset Service Provider) authorisation. Operators already registered as PSANs should monitor AMF guidance on the transition timeline and the additional requirements a full CASP authorisation will impose. The practical effect for an inbound operator today is that a PSAN registration remains the entry point while the MiCA clock runs.
Reaching out early matters. The process above describes the standard path. Your facts – the entity structure, the user base geography, the currency flows – change the analysis materially.
For a scoped assessment of your France entry structure, contact OBOLUS at info@oboluslaw.com. Map your options
Who Needs a PSAN Registration in France?
Any legal entity that provides one or more of the AMF's listed digital-asset services to clients in France must register as a PSAN, regardless of where the entity is incorporated. The reach test is service-directed at French residents, not entity domicile. A BVI-incorporated exchange actively marketing to French users and settling in euros is, in the AMF's stated position, providing PSAN-category services in France.
This extraterritorial reading is not theoretical. The AMF has published warnings against unlicensed service providers and maintains a public blacklist. Operators that appear on that list face reputational damage, banking refusals and regulatory referrals. In our cross-border practice, we regularly advise operators who assumed their offshore licence was sufficient for EU clients. It is not, and France is one of the more assertive EU jurisdictions in applying this principle.
The carve-outs are narrow. Pure software and infrastructure providers with no client-facing service element may fall outside the perimeter. Operators offering services exclusively to professional counterparties under defined thresholds may qualify for a lighter-touch pathway. Both carve-outs require careful factual analysis – they are not self-applying.
What Does the PSAN Registration Process Involve?
The PSAN registration process is a structured AMF review covering the applicant's legal form, beneficial ownership, AML/CFT programme, IT security posture, and the fitness and propriety of its directors and beneficial owners. The AMF reviews the dossier and may request supplementary information; the process is iterative rather than a single-submission review.
Key elements of the dossier include: a detailed description of the services and the technical architecture supporting them; an AML/CFT manual and risk classification; a GDPR-compliant data-processing register; evidence of internal controls; and individual questionnaires for every person holding a qualifying function. The requirements are substantive. A thin dossier draws AMF questions that extend the timeline materially.
An optional – but commercially significant – enhancement is the visa (approval) track, which goes beyond the baseline registration and carries greater regulatory standing. Operators targeting institutional clients, or those negotiating PSP and banking relationships, often find that the visa materially improves their counterparty negotiations. We have seen banking refusals reverse once an operator moved from registered to visa status.
Timeline for the registration track is not fixed by statute; the AMF's review period varies depending on dossier completeness and the activity categories requested. Operators should plan for a process measured in months, not weeks, particularly for first-time applicants without French regulatory experience.
How Does a PSP or Acquiring Agreement Work Alongside PSAN Status?
A PSP or acquiring agreement is the commercial and legal contract through which a licensed payment institution or acquirer provides fiat payment services to a PSAN-registered entity – covering card acceptance, SEPA credit transfers, instant payment rails and, where applicable, acquiring for merchants settling in fiat after a crypto conversion. The acquiring relationship is distinct from the PSAN registration and must be negotiated separately with a licensed counterparty under ACPR supervision.
In practice, securing this agreement is the harder commercial task. Banks and EMIs conducting their own due diligence on a crypto business apply a risk-based framework that typically includes: review of AML/CFT programme quality; assessment of the client's user base and transaction volumes; Travel Rule compliance posture; and, increasingly, a review of whether the operator holds or is progressing toward PSAN registration. An operator that cannot demonstrate PSAN status – or a credible plan to obtain it – will find most French and EU-regulated payment counterparties unwilling to engage.
The Travel Rule (the obligation under FATF Recommendation 15 to pass originator and beneficiary data with a virtual-asset transfer) is now a live expectation in French AMF/ACPR supervised entities. Payment counterparties will ask how the PSAN handles Travel Rule compliance. A PSAN that cannot demonstrate a functional Travel Rule solution faces friction at the banking negotiation stage, not just the regulatory one.
In our practice, we map the AML posture, Travel Rule architecture and PSAN registration timeline concurrently with the PSP outreach strategy. Starting the PSP conversation before the PSAN dossier is in order produces delays and refusals that a sequenced approach avoids.
What Is the Cross-Border Reality for Inbound Operators?
For a business sitting between a non-EU holding structure and a French-resident client base, the legal question turns on more than French registration alone. The entity that holds the PSAN registration, the entity that contracts with the PSP, and the entity that books revenue may be different legal persons – and each relationship carries its own regulatory and tax consequence.
MiCA passporting changes part of this picture. Under MiCA, a CASP authorised in one EU member state may passport services across the EU/EEA without local licensing in each member state. France is an EU member state; once MiCA transitions are complete, an operator authorised in, say, Lithuania or Malta under the CASP regime will not need a separate French authorisation to serve French clients in the same activity categories. The PSP relationship, however, remains a commercial negotiation – passporting of the CASP licence does not deliver a fiat-rail relationship.
Banking for the holding structure is a separate problem. Non-EU holding entities – BVI, Cayman, UAE-incorporated parents – routinely face account-opening refusals at French banks. The practical solution we advise is a correctly structured EU operating subsidiary, with the PSAN registration at that subsidiary level, and PSP onboarding negotiated for that entity. The holding structure's banking is then handled in a jurisdiction whose banks are more comfortable with non-EU digital-asset entities, working with allied counsel in the relevant jurisdiction.
Tax interaction is material. France applies corporate income tax to the profits of a French-registered entity. A French PSAN subsidiary that is also the acquiring party under the PSP agreement will be subject to French tax on its net margin. Transfer-pricing rules apply to intra-group flows between the French subsidiary and a non-EU parent. Getting this right at the structuring stage – before the PSAN application is filed – avoids restructuring costs later.
In a recent matter, a European payments company sought to expand its existing EMI services into crypto asset brokerage in France. The group held an EMI licence in a second EU member state. We advised on the scope of that licence's passporting rights, identified the activity categories requiring a separate PSAN filing in France, and structured the intra-group agreement between the EMI entity and the proposed French PSAN entity to correctly allocate payment-processing and brokerage functions. The revised structure avoided a French permanent-establishment exposure that had not been identified in the group's initial plan.
If a prior application stalled or a banking relationship closed, a second read of the structure can surface the reason and the route forward. Write to OBOLUS at info@oboluslaw.com. Map your options
AML, Travel Rule and the AMF's Supervisory Expectations
AML/CFT compliance is not a box-ticking exercise under the AMF's PSAN supervisory framework; it is the primary lens through which both the registration review and the ongoing supervisory relationship are conducted. France has transposed FATF Recommendation 15 and the EU's Transfer of Funds Regulation into its national AML/CFT framework, meaning PSAN-registered entities must implement the Travel Rule for virtual-asset transfers above the applicable threshold.
The AMF and ACPR conduct joint thematic reviews of PSAN-registered entities. Findings from those reviews – published in AMF supervisory reports – consistently identify weaknesses in: customer risk classification, particularly for corporate clients; transaction monitoring calibration for crypto-specific patterns; and Travel Rule data collection and transmission. An operator whose AML programme is generic rather than crypto-specific will fail the supervisory test even if it passed the registration review.
Travel Rule implementation requires a technical solution. Several inter-VASP messaging protocols operate in the market; the choice of protocol affects which counterparties a PSAN can transfer assets to, and affects the PSP's own due diligence requirements. Operators we advise select a Travel Rule solution before – not after – filing the PSAN application, because the technical architecture is part of the registration dossier.
The ACPR's expectations on payment-institution AML mirror those of the AMF. A PSP onboarding a PSAN client will require sight of the PSAN's AML programme, its customer due-diligence procedures and, specifically, its sanctions screening coverage. OFAC, EU consolidated sanctions lists and the French domestic list all apply. A gap in any one of these layers is a PSP due-diligence failure.
Self-Assessment: Are You Ready to Engage the French Regulators?
Before committing to a France entry, an operator should be able to answer each of the following affirmatively. If any answer is uncertain, the corresponding workstream needs to be resolved before the AMF dossier is submitted.
- Is the legal entity that will hold the PSAN registration incorporated or registered in France, or is there a plan to establish it?
- Have all PSAN-category activities the operator intends to provide been identified and mapped against the AMF's activity list?
- Is there a written AML/CFT programme tailored to virtual-asset risks, including a customer risk-classification matrix and a transaction-monitoring policy?
- Have the beneficial owners and proposed directors completed the required fitness-and-propriety documentation, and are any prior regulatory incidents in other jurisdictions addressed?
- Has the operator selected a Travel Rule solution and confirmed technical compatibility with its intended counterparties?
- Has a PSP or EMI been approached, and has the PSAN registration timeline been communicated to that counterparty?
- Has the tax treatment of the French operating entity – including transfer pricing on intra-group flows – been reviewed by qualified counsel?
A common assumption among operators entering France is that a single offshore licence – a BVI VASP registration, a Cayman filing, or a light-touch EU registration in another member state – is sufficient to serve French clients commercially. It is not. The AMF applies its registration requirement based on where the service is directed, not where the operator is incorporated. The practical consequence is that an operator without PSAN status, or a credible MiCA-transition plan, cannot access the French banking and payment-services market on acceptable terms.
Which Operator Profile Should Pursue Which Route?
Different operator profiles require different sequencing of the France entry.
Profile A – Pure crypto-to-crypto exchange with no fiat rails. If the operator takes no fiat deposits and makes no fiat withdrawals, the ACPR payment-services track may not apply directly. The operator still requires PSAN registration for the trading-platform and order-reception activities. The PSP relationship becomes relevant only when fiat onboarding is added to the product. The recommended path is: PSAN registration first, PSP outreach second, timed to coincide with the planned fiat-product launch.
Profile B – Crypto broker or exchange with fiat deposit and withdrawal. This is the most common profile for an inbound operator. Both tracks are required concurrently. The PSAN dossier and the PSP due-diligence package should be prepared in parallel. Timeline risk concentrates at the PSP negotiation, which tends to be slower than the AMF review when the operator has no prior EU regulated history. Expect the PSP onboarding to be the critical path.
Profile C – EU-licensed EMI or payment institution adding crypto services. An existing ACPR-supervised entity adding PSAN-category services needs the AMF registration for those activities, but the payment-services infrastructure is already in place. The primary workstream is identifying which crypto activities are being added, ensuring the AML/CFT programme covers them, and filing with the AMF. Timeline is typically shorter than for a greenfield entry.
Profile D – Non-EU parent establishing a French subsidiary under MiCA. The parent entity holds no EU licence. The recommended structure is a French SAS or SA subsidiary, PSAN registration at that entity, and a planned conversion to CASP authorisation once AMF guidance on the transition is final. Banking for the French subsidiary is pursued through EU-supervised payment institutions comfortable with the crypto sector; the parent's own banking is handled separately.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital-Asset Businesses – structuring fiat rails and payment-institution relationships across jurisdictions
- Fiat On/Off-Ramp Banking in El Salvador – comparative analysis of fiat-rail strategy in an alternative regulatory environment
- Airdrop Legal Structuring in Australia (AUSTRAC) – AUSTRAC registration and cross-border structuring for token distribution
FAQ
Why do banks close crypto company accounts?
Banks close or refuse crypto company accounts primarily because of perceived AML/CFT risk. Crypto transactions are pseudonymous, cross-border and difficult to monitor under standard banking systems. Banks subject to ACPR supervision must apply a risk-based approach to customer acceptance; a crypto operator without a well-documented AML programme, a recognised regulatory status such as PSAN registration, and a clear Travel Rule solution will typically exceed the bank's internal risk appetite. Demonstrating regulatory standing and a mature compliance framework is the most reliable route to a stable banking relationship.
How can a VASP onboard with an EMI?
A VASP (virtual asset service provider) seeking EMI onboarding must typically provide: evidence of regulatory registration or licensing in its home jurisdiction; a detailed description of the business model, expected transaction volumes and client types; a copy of the AML/CFT programme; evidence of Travel Rule compliance; and a sanctions-screening policy. EMIs conduct their own due-diligence review before onboarding a VASP as a client. The process resembles a regulatory application in scope and depth. Operators who prepare a complete onboarding pack before approaching an EMI report materially faster onboarding timelines.
What does client-money safeguarding require?
Client-money safeguarding requires a payment institution or EMI to hold funds received from or for payment-service users in a designated account at a central bank or credit institution, or covered by an eligible insurance policy – segregated from the institution's own funds. The obligation arises under the EU Payment Services Directive framework transposed into French law. For crypto operators contracting with a PSP or EMI, the safeguarding obligation sits with the licensed payment institution, not the PSAN. However, the PSAN's own custody obligations for digital assets are separate and arise under the AMF's PSAN regime.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than seventy jurisdictions, on disputes and on-chain asset recovery across more than twenty-five forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, payment and custody stack across operating, custody and payment layers before a client commits to a market-entry structure. To discuss your situation, contact info@oboluslaw.com or message us via t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in EU and cross-border VASP registration, MiCA transition analysis and payment-services regulatory structuring for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.