Operating a payment business in Kazakhstan without the right licence exposes the enterprise to enforcement action, frozen settlement rails and the abrupt loss of banking. For digital-asset businesses, the Astana International Financial Centre (AIFC) – a common-law financial free zone governed by Astana Financial Services Authority (AFSA) regulation – offers a structured path to a payment service provider (PSP) authorisation and a legally binding acquiring agreement. The AIFC regime is grounded in AFSA's rules on payment systems and digital-asset services, creating a coherent stack for businesses that need fiat rails alongside crypto-asset activity. This page sets out the regulatory basis, the practical process, the cross-border interaction with banking and tax, and the decision point for inbound operators.
What is the AIFC PSP and Acquiring Regime?
The AIFC gives payment service providers and acquiring businesses a dedicated authorisation track under the AFSA payment-services rules. Authorisation from AFSA grants the right to issue payment instruments, execute payment transactions, operate merchant acquiring services, and – critically for digital-asset businesses – integrate fiat settlement into a broader crypto infrastructure. This is not a registration-lite arrangement: AFSA applies conduct rules, capital expectations, safeguarding obligations and ongoing supervision comparable to mid-tier financial-centre standards. The acquiring agreement – the contract between a PSP and a merchant or exchange – must be structured to meet AFSA's conduct and disclosure expectations before it is executed.
The common-law basis of the AIFC is a structural differentiator. AIFC courts apply English-origin commercial law. Contract disputes, payment disputes and regulatory proceedings all sit within a predictable legal environment. For a cross-border operator whose counterparties include EU-regulated entities, the common-law anchor reduces friction in contract negotiation and in any downstream dispute resolution. In our cross-border practice, we have seen operators significantly underestimate the value of this legal-system alignment when selecting an operating hub.
AFSA's digital-asset trading facility and custody authorisations sit alongside the payment-services framework, allowing a single AIFC-regulated entity to hold multiple activity permissions. That stacking capacity matters for businesses running exchange, custody and acquiring functions together. Regulators elsewhere – including VARA in Dubai and the FSRA in Abu Dhabi – have moved toward similar multi-permission structures, but the AIFC's common-law base and Central Asian market access give it a distinct profile for operators targeting the CIS and Kazakhstan domestically.
For a scoped assessment of your PSP or acquiring structure in the AIFC, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity type, the user base, the banking counterparties – change the analysis.
Who Needs a PSP or Acquiring Authorisation in the AIFC?
Any business executing payment transactions, issuing payment instruments or operating a merchant acquiring service within or from the AIFC must hold an AFSA payment-services authorisation, unless a specific exemption applies. For digital-asset businesses, the trigger is often indirect: a crypto exchange or custodian that processes fiat on-ramps and off-ramps, settles merchant payments in stablecoins, or operates a card-linked crypto wallet is typically conducting regulated payment-service activity under the AFSA framework.
A common assumption is that a single offshore licence – perhaps held in a Caribbean jurisdiction – is sufficient to serve clients globally, including merchants and users in Kazakhstan and the broader CIS region. That assumption is incorrect. The AIFC's jurisdictional perimeter extends to activity conducted within the free zone and to services actively marketed to participants in Kazakhstan's financial market. Cross-border service without the appropriate AFSA authorisation can expose the business to enforcement by AFSA and, separately, to regulatory action under Kazakhstan's national framework. We regularly advise operators who have inadvertently triggered the AIFC perimeter through merchant-acquiring activity structured offshore.
The practical question is whether the business's fiat-settlement or acquiring activity has a sufficient nexus to the AIFC or Kazakhstan. The analysis turns on: where the acquiring agreement is signed and governed, where the merchants or counterparties are located, where settlement flows and where the issuing entity sits. AFSA has not published a bright-line territorial rule; the assessment is fact-specific and, in borderline cases, benefits from early regulator engagement.
What Does the AIFC PSP Application Process Involve?
The AFSA authorisation process for a payment-services firm moves through defined stages, though exact timelines vary by licence category and the completeness of the application package. In our practice, operators who submit a complete, well-prepared file typically achieve authorisation within a matter of weeks for lighter-touch categories, with more complex multi-permission applications taking longer. Pre-application engagement with AFSA – a standard feature of the process – allows the business to confirm scope, clarify regulatory expectations and reduce the risk of post-submission queries.
The core documentation package for a PSP or acquiring application includes a detailed business plan covering the payment-services model, technology infrastructure, risk framework and target market; a description of the acquiring-agreement template and merchant-onboarding process; an AML/CFT policy aligned to FATF Recommendation 15 and AFSA's own AML rules; a compliance monitoring plan; fitness-and-propriety documentation for controllers and senior management; and evidence of minimum capital, which varies by category and should be confirmed from current AFSA rules at the time of application.
For digital-asset businesses adding a payment-services permission to an existing or concurrent AFSA digital-asset authorisation, the application is structured to demonstrate how the payment layer integrates with the broader regulated model. The acquiring-agreement template is reviewed for compliance with AFSA's conduct rules before submission. In our cross-border practice, we draft the acquiring-agreement framework in parallel with the application, rather than after authorisation – a sequencing decision that materially shortens time-to-operational-readiness.
Post-authorisation, the firm must maintain ongoing capital adequacy, submit regulatory returns, notify AFSA of material changes and ensure that every acquiring agreement executed falls within the scope of the authorised activity. Permitted activities are defined by reference to the AFSA authorisation, not by the internal labels the business uses for its services.
How Should an AIFC Acquiring Agreement Be Structured?
An acquiring agreement under the AIFC regime must align to AFSA's conduct rules on disclosure, fees, settlement timing, chargeback rights and termination. Beyond regulatory compliance, the acquiring agreement is a commercial instrument that allocates settlement risk, interchange economics and liability for fraud between the PSP and the merchant. For digital-asset businesses, the agreement often needs to address additional dimensions: settlement in stablecoin or fiat, the conversion mechanic, the treatment of on-chain transaction finality, and the interaction with any custodial arrangement held by the PSP.
A well-drafted acquiring agreement makes four things explicit. First, the payment flow: which entity holds merchant funds, at what point in the settlement cycle and on what basis (safeguarding, trust or contractual debt). Second, the fee structure: interchange, scheme fees, currency-conversion costs and any crypto-settlement premium, all described in a transparent schedule. Third, the liability allocation: who bears the chargeback exposure, what the merchant's fraud-management obligations are, and how disputes are escalated. Fourth, the governing law and dispute-resolution clause: AIFC courts applying AIFC law is the standard choice for an AFSA-authorised PSP, though parties with EU counterparties sometimes negotiate England and Wales as an alternative or secondary seat.
In a recent cross-border matter, a payment technology company sought to execute a merchant-acquiring programme across Kazakhstan and two adjacent markets. The acquiring-agreement template used by the business had been drafted for an EU regulatory environment and contained safeguarding provisions incompatible with the AFSA framework. We restructured the agreement to align with AIFC conduct rules, revised the settlement-timing provisions and produced a jurisdiction schedule clarifying the regulatory basis in each market. The programme launched without a pre-execution gap in compliance coverage.
How Do Fiat Rails and Banking Work for AIFC PSPs?
Securing a correspondent banking relationship or a settlement account is, in practical terms, as important as holding the AFSA authorisation itself. Banks globally continue to apply enhanced due diligence to PSPs and to digital-asset businesses, and the intersection of the two categories creates a well-documented friction point. The AIFC's status as a regulated, common-law financial centre with a recognized supervisory regime generally improves the risk profile that correspondent banks assign to an AIFC-authorised firm, compared with entities holding only offshore registrations. That said, the bank's own compliance function will conduct its own assessment, and the AFSA authorisation is a necessary but not sufficient condition for account onboarding.
Operators we advise routinely underestimate the documentation burden at the banking stage. A correspondent bank or EMI (electronic money institution) onboarding an AIFC PSP will review: the AFSA authorisation letter and permitted-activity schedule; the AML/CFT programme; the business plan and merchant-onboarding policy; the acquiring-agreement template; the beneficial-ownership structure; and the source-of-funds position for the initial capital. For digital-asset businesses, the bank will typically also request a description of the on-chain infrastructure, the stablecoin exposure, the forensics and monitoring tools in use, and the process for screening merchants against sanctions lists.
EMI onboarding – engaging a licensed electronic money institution as a settlement partner rather than a full bank – has become a practical route for AIFC PSPs that cannot yet satisfy a tier-one bank's onboarding criteria. The EMI holds the settlement account and provides the fiat rails; the AIFC PSP operates the acquiring layer and the merchant relationship. The two-entity structure requires careful contractual engineering to ensure that the acquiring agreement, the EMI services agreement and the client-money safeguarding obligations are aligned. We structure these arrangements as an integrated mandate: licence, agreement and banking documentation prepared together.
If a prior banking application stalled or an account was closed, a second read of the structure can surface the reason and the route forward. Write to us at info@oboluslaw.com.
How Does the AIFC PSP Interact With Tax and Cross-Border Structuring?
The AIFC operates within Kazakhstan's broader tax framework, but with specific incentives for AIFC-registered entities. The tax treatment of payment-services income, acquiring fees and digital-asset settlement flows is jurisdiction-specific and should be confirmed with reference to current AIFC and Kazakhstan tax rules. As a general principle, the entity that holds the AFSA authorisation, executes the acquiring agreements and receives the fee income is the entity that generates the primary taxable presence. Structuring the PSP function in a holding arrangement that separates fee income from the authorised entity risks both regulatory and tax-authority scrutiny.
For groups operating across multiple jurisdictions – holding a MiCA CASP (Crypto-Asset Service Provider) authorisation in the EU alongside an AIFC PSP – the transfer-pricing position on intercompany service fees and the permanent-establishment risk in both Kazakhstan and the EU must be mapped in advance. In our practice, we engage on the tax and banking stack at the same time as the licence application, not after authorisation has been granted. The sequencing matters: a licence structure that creates an unintended taxable presence in a high-cost jurisdiction can offset the economics of the AIFC operation.
A cross-border group should also consider the interaction between the AIFC PSP and the Travel Rule – the FATF-grounded obligation to pass originator and beneficiary data with a transfer. Where the PSP processes fiat payments that originate from or settle to a crypto wallet, the Travel Rule data chain must be maintained through the settlement cycle. AFSA's AML rules incorporate the FATF standards; the acquiring agreement and the EMI services agreement should both address data-passing obligations explicitly.
Which Operator Profile Should Consider an AIFC PSP Structure?
Not every digital-asset business needs a standalone AIFC PSP authorisation. The decision turns on the business model, the merchant base and the existing licence stack.
A crypto exchange or OTC desk that settles fiat for CIS-based merchants and needs a compliant acquiring layer is a strong candidate. The AIFC authorisation provides the regulatory basis for the acquiring agreement; the common-law contract framework reduces dispute risk with counterparties; and the AFSA-supervised structure materially improves the banking and EMI onboarding position. Indicative build time, from entity formation to operational launch, is typically measured in months, not years – though the specific timeline depends on the readiness of the compliance documentation and the responsiveness of the banking partner.
A payment technology company expanding from the EU into Central Asia, holding a MiCA CASP authorisation, will typically need to add an AIFC layer rather than passport the EU licence. MiCA passporting operates within the EU/EEA perimeter; it does not extend to the AIFC or Kazakhstan. A dual-jurisdiction structure – EU CASP plus AIFC PSP – requires a clear delineation of which entity serves which market and on what regulatory basis. The key risk is inadvertent regulatory arbitrage: routing activity through the lower-cost entity to serve users who should be served by the higher-regulated entity.
A stablecoin issuer or custodian looking to offer acquiring services to merchants in the CIS region should approach the AIFC structure as an integrated build: the custodial permission, the payment-services authorisation and the acquiring-agreement template designed together. Treating them as sequential workstreams adds time and frequently requires retrospective amendment of agreements drafted without the full regulatory picture in view.
For operators who are not yet AIFC-licensed, a lighter-touch entry is a branch or representative presence in the AIFC combined with a referral arrangement with an AFSA-authorised PSP. This provides market access while the full authorisation application is in progress. The referral arrangement must be structured to avoid inadvertent regulated-activity performance by the unlicensed entity.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital-Asset Businesses – how we structure the full payment and banking layer for licensed operators
- De-Risking and Account Closure Defence in the BVI – what to do when a bank exits a crypto relationship
- Tax Regime for Digital Assets in Lithuania – the EU tax dimension for groups with an AIFC and EU licence stack
FAQ
Why do banks close crypto company accounts?
Banks close crypto accounts primarily because of compliance risk assessment: the AML/CFT profile of a crypto business is perceived as high, and the bank's cost of supervision exceeds the commercial value of the relationship. The specific triggers include inadequate disclosure of the business model, insufficient transaction monitoring, sanctions-screening gaps, and the absence of a recognised supervisory licence. An AFSA or MiCA authorisation does not guarantee account retention, but it materially improves the bank's ability to risk-rate the relationship. Proactive disclosure and a well-documented compliance programme are the practical defence.
How can a VASP onboard with an EMI?
A VASP (virtual asset service provider) seeking to onboard with an EMI must present a package comparable to a full bank's due-diligence requirements: a regulatory licence or registration, a detailed AML/CFT programme, a business plan describing the fiat-flow architecture, a beneficial-ownership register, and – increasingly – evidence of on-chain monitoring tools. The EMI will assess the VASP's merchant base and geographic exposure. Where the VASP holds an AFSA or CASP authorisation, the supervised status is a positive signal. The commercial terms of the EMI services agreement should address settlement timing, float management and termination rights carefully.
What does client-money safeguarding require?
Client-money safeguarding requires a payment-services firm to hold funds received from clients in a way that keeps them identifiable and separated from the firm's own assets. Under the AFSA regime and most flagship frameworks, this means maintaining a dedicated safeguarding account at an approved credit institution, holding an insurance or guarantee equivalent, or applying a combination. The firm must be able to return client funds promptly if it becomes insolvent. The acquiring agreement and the EMI services agreement must both address the safeguarding mechanism explicitly, confirming which entity holds the safeguarding obligation at each point in the settlement cycle.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – structuring licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in AFSA/AIFC payment-services authorisation and cross-border digital-asset compliance.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.