EST · MMXXVI
Home/Jurisdictions/Uae Adgm/PSP and acquiring agreement in Abu Dhabi Global Market (ADGM)
Banking, Payments & EMI Onboarding

PSP and acquiring agreement in Abu Dhabi Global Market (ADGM)

Psp and acquiring agreement in Abu Dhabi Global Market (ADGM). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk

Operating a payment service provider or an acquiring business inside Abu Dhabi Global Market (ADGM) without the right regulatory foundation exposes the business to enforcement action, abruptly frozen settlement rails and the loss of the banking relationships that keep fiat moving. The Financial Services Regulatory Authority (FSRA), ADGM's prudential and conduct regulator, requires entities conducting regulated payment activities to hold appropriate authorisation before they accept merchant flows, issue acquiring agreements or touch client money. A PSP or acquirer that treats ADGM as a pass-through without proper standing misreads both the regime and the commercial risk.

This page sets out the regulated basis for PSP and acquiring activity in ADGM, the inbound application process, the cross-border interaction between your payment licence, crypto banking and fiat rails, and the practical decision point for operators evaluating the Abu Dhabi hub.

What does the FSRA require from a PSP or acquirer in ADGM?

Any firm conducting regulated financial services within ADGM – including the operation of payment systems, the provision of money services and the issuance or administration of payment instruments – must hold an FSRA financial services permission covering those specific activities. ADGM operates a common-law jurisdiction modelled on English law, and the FSRA applies a rigorous activity-based authorisation model: the licence must match the regulated activity precisely. Offering acquiring services, processing merchant settlements or holding client funds in transit without the correct permission is not a grey area – it is an unauthorised activity under the FSRA framework.

For digital-asset businesses, the stakes compound. A firm that also handles virtual assets alongside fiat payment flows falls within the FSRA's dedicated virtual-asset regime. That regime introduces additional requirements around segregation, safeguarding and the treatment of recognised virtual assets. Operators we advise regularly underestimate how quickly a payments business that accepts stablecoin settlement becomes subject to both the payment-service rules and the virtual-asset rules simultaneously.

The FSRA's supervisory posture has tightened as the UAE's broader regulatory environment has matured. Regulators across the leading hubs, including the FSRA, increasingly expect applicants to demonstrate operational substance – not merely a registered address – before granting permission. That means local governance, a genuinely staffed compliance function and documented outsourcing arrangements where any part of the technical stack sits offshore.

Who needs a PSP or acquiring licence in ADGM?

The obligation to seek FSRA authorisation attaches to the activity, not to the label the business applies to itself. Four operator profiles recur in our practice.

First, a dedicated payment service provider that settles merchant transactions in fiat or stablecoin, routes funds across borders and holds float in client accounts. Second, an acquirer that enters into contractual relationships with merchants to accept card-based or account-to-account payments, then nets and settles those flows. Third, a crypto exchange or custodian that adds a fiat gateway – accepting bank transfers, issuing settlement to merchants or offering card-funded on-ramps – because that ancillary payment layer triggers the regulated payment activity threshold independently of the exchange licence. Fourth, a virtual asset service provider (VASP) – a firm offering exchange, custody or transfer services in virtual assets – that routes settlement through ADGM-incorporated entities or uses ADGM-licensed counterparties as settlement agents.

All four profiles share a common structural question: does the activity, as actually conducted from or through ADGM, require a standalone payment permission, or is it covered by an existing broader licence? That analysis is entity-specific and fact-specific. The FSRA does not issue comfort letters by default; the authorisation question must be resolved before launch.

How does the ADGM authorisation process work in practice?

The FSRA application process for a regulated payment entity in ADGM follows a structured sequence, and the quality of the application file is the primary determinant of timeline. A poorly prepared submission does not fail immediately – it generates rounds of clarification requests that can extend the process by months.

The process begins with regulatory scoping: mapping the activities the business will conduct to the specific regulatory permissions required, identifying whether any prior authorisation in another jurisdiction is relevant and assessing whether the entity structure is appropriate. In our cross-border practice, we have seen operators spend significant time and capital building an entity structure that the FSRA later regards as insufficiently local. Correcting that post-submission is expensive.

The core application package typically includes a detailed business plan, a financial model, draft governance documents, a compliance and AML/CFT programme, a risk management framework, technology and outsourcing documentation and biographical information on approved persons. The FSRA conducts its own vetting of controllers, senior managers and key function holders. Approved person assessments are thorough and are not a formality.

Once the application is accepted as complete, the FSRA's review proceeds through a structured assessment phase. The regulator may request supplementary information or interviews. Timelines vary by complexity; straightforward applications from well-capitalised, experienced operators with clean approved-person profiles tend to move faster than structurally complex submissions. We describe timelines qualitatively because the FSRA has not published fixed statutory windows for payment-service authorisations, and any specific figure published elsewhere should be treated with caution.

Capital requirements are set by the FSRA based on activity type and the risk profile of the business. The FSRA has not published a single universal minimum that applies to all payment entities; the applicable own-funds requirement is determined during the authorisation process and is proportionate to the scale and risk of the proposed activity. Operators should build their financial models on the basis that the FSRA will set a capital floor, and then size their runway accordingly.

For a scoped assessment of your ADGM payment authorisation path, the analysis begins with your activity map, not your business plan. Map your options before you file.

How is a PSP and acquiring agreement structured under ADGM law?

An acquiring agreement in ADGM is governed by ADGM's English-law-based contract law, and its enforceability depends on whether the acquiring entity holds the requisite FSRA permission at the time of signing and throughout performance. An agreement signed by an unauthorised entity is not merely unenforceable – it exposes the directors and controllers to personal regulatory liability.

A well-constructed acquiring agreement for an ADGM-regulated entity addresses several layers simultaneously. The payment terms must reflect the FSRA's client-money safeguarding requirements: funds held on behalf of merchants cannot be commingled with proprietary funds, and the agreement must specify the account structures, ring-fencing arrangements and reconciliation obligations that the FSRA expects to see. Where the settlement currency includes virtual assets – stablecoins being the most common scenario – the agreement must also address the FSRA's virtual-asset classification framework and any additional disclosure or disclosure obligations that flow from that.

Cross-border payment flows raise a second structural question. An acquiring entity seated in ADGM that routes settlement to merchants in other jurisdictions may trigger regulatory obligations in those destinations. The EU's payment-services regime, Singapore's Payment Services Act and the UK's FCA registration requirements each have extraterritorial dimensions. In our practice, we map those outbound obligations at the drafting stage so the acquiring agreement does not inadvertently document activity that the entity is not permitted to conduct in the destination jurisdiction.

The Travel Rule – the obligation under FATF Recommendation 15 and its implementing regulations to pass originator and beneficiary data alongside a virtual-asset transfer – applies wherever the acquiring chain involves a virtual-asset transfer between VASPs. ADGM-licensed entities are not exempt. The acquiring agreement should specify the data-sharing protocol, the technical standard adopted and the fallback where a counterparty is non-compliant.

How does crypto banking and fiat-rail access work for ADGM-licensed operators?

Fiat-rail access is, in practice, as consequential as the licence itself. A PSP or acquirer without a stable settlement bank is a regulated entity that cannot operate. This is the friction point operators most frequently underestimate, and it is the most common reason a correctly licensed business fails to reach commercial launch.

Banks in the UAE and internationally have developed increasingly granular onboarding criteria for payment-service businesses that touch digital assets. The presence of an ADGM licence and a properly structured compliance programme materially improves the probability of a successful bank onboarding, but it does not guarantee it. Banks conduct their own risk assessments, and a business model that involves stablecoin settlement, high-volume cross-border transfers or exposure to jurisdictions that carry elevated FATF risk will face a longer and more intensive review than a conventional fiat PSP.

In our practice, we structure the banking and EMI onboarding workstream in parallel with the licensing process, not after it. The two processes inform each other: the compliance documentation prepared for the FSRA application serves as the foundation for the bank's KYB review; the bank's correspondent requirements can shape how the entity's settlement flow is documented in the operating model. A business that builds these two workstreams sequentially – licence first, banking later – often loses months and occasionally has to restructure the entity to satisfy banking criteria that could have been anticipated at the design stage.

Where direct UAE banking is not available at launch, the interim solution for many operators is a relationship with a regulated EMI (electronic money institution) in a compatible jurisdiction. EMIs authorised under MiCA in the EU or registered with the FCA in the UK can provide IBAN-based settlement and payment processing while the primary banking relationship is established. That interim structure must itself be documented correctly: the FSRA will want to understand the full payment chain, and an undisclosed EMI acting as a shadow settlement layer creates a supervisory problem.

What does the cross-border licence, tax and banking stack look like?

For most operators considering ADGM, the payment licence is one layer of a wider cross-border structure. The entity that holds the FSRA payment permission rarely operates in isolation: it sits alongside a holding company, a custody entity, a technology subsidiary or a fund structure, and those elements may be in different jurisdictions. Getting the intercompany relationships right – in terms of regulatory treatment, tax and transfer pricing – is as important as the licence itself.

ADGM offers significant structural advantages for an international operator. It is a zero-corporate-tax environment for most income earned by entities operating within the free zone, subject to the UAE's broader corporate-tax framework which has introduced a federal corporate-tax rate that applies to certain in-scope entities. Operators must assess whether their ADGM entity's income falls within the free-zone qualifying income rules or within the scope of the federal rate – that analysis requires specific tax advice and is not a generic answer.

Transfer pricing between the ADGM entity and related-party entities in other jurisdictions is a live issue for payment businesses that route significant fee income. The FSRA requires transparency in intercompany arrangements, and the UAE's transfer-pricing rules – which align broadly with OECD principles – apply. An acquiring business that strips fee income to a low-substance offshore entity while booking regulatory substance in ADGM will face challenge both from the FSRA (on the substance point) and from tax authorities (on the transfer-pricing point).

The banking layer introduces a third axis. A business banking in ADGM, settling through an EU EMI and holding custody assets in a BVI or Cayman entity must manage three regulatory relationships, three compliance frameworks and potentially three sets of AML reporting obligations simultaneously. In our cross-border practice, we have seen businesses where no single adviser had visibility across all three layers, and the gaps between them created the precise enforcement exposure the business was trying to avoid.

If your licensing and banking workstreams are running in parallel and you need both mapped to a single operating model, the time to align them is before the FSRA application is filed. Map your options with OBOLUS.

A recent matter: ADGM payment licence and banking alignment

In a recent cross-border mandate, a digital-payments operator had obtained preliminary corporate registration in ADGM and begun drafting its acquiring agreement before engaging counsel on the regulatory and banking layers. The draft agreement described activity – specifically, the holding of merchant float in a pooled account – that would constitute a regulated payment activity requiring explicit FSRA permission the entity did not yet hold. Separately, the banking outreach had targeted a UAE correspondent bank using a business description that characterised the stablecoin settlement component as incidental, a characterisation the bank's compliance team rejected at the KYB stage.

We restructured the entity's activity map to separate the regulated payment holding function from the technology-service layer, prepared the FSRA application with a business model that correctly characterised both the fiat and virtual-asset components, and ran the bank-onboarding preparation as a parallel workstream using the compliance documentation built for the FSRA file. The operator reached authorised status and achieved banking coverage within a commercial timeframe. No restated capital raise was required.

ADGM, VARA or an EU CASP: which profile fits which structure?

The decision between ADGM, Dubai's VARA regime and an EU CASP authorisation under MiCA is not a simple ranking. Each suits a different operator profile, and a serious cross-border payment business often needs representation in more than one.

An operator whose primary merchant base and banking relationships are in the Gulf, whose principals have a UAE nexus and who wants access to the DIFC and the Abu Dhabi financial community will find ADGM a natural fit. The FSRA's common-law framework is intelligible to international counterparties, the free-zone structure offers tax clarity and the DIFC Courts provide a dispute-resolution forum that sophisticated institutions treat as equivalent to London or Singapore. The constraint is that an ADGM authorisation does not create passporting rights into the EU – a business that wants to serve EU merchants or EU-regulated financial counterparties needs either a MiCA CASP authorisation or a relationship with an EU-regulated partner entity.

A business whose user base and counterparties are primarily EU-based will find MiCA the more direct route. The CASP authorisation under MiCA, once obtained from a national competent authority in a qualifying member state, carries passporting rights across the EU and the EEA. The trade-off is that EU regulatory requirements – particularly around AML, Travel Rule data and consumer protection – are more prescriptive and the supervisory intensity is rising as ESMA and national competent authorities build out their MiCA implementation capacity.

VARA in Dubai is the appropriate path for an operator whose primary activity is virtual-asset specific – exchange, custody, management or advisory – and whose geographic focus is the UAE mainland. VARA and the FSRA are not substitutes: VARA covers mainland Dubai; ADGM and its FSRA cover the Abu Dhabi free zone. A business operating across both must manage both regulatory relationships.

A profile that fits none of those single-jurisdiction paths – a global payment infrastructure business serving merchants across multiple regions – will typically require a layered structure: an ADGM entity for Gulf and institutional flows, a MiCA-compliant CASP or EMI for EU settlement and potentially a Singapore MAS-licensed entity for Asia-Pacific. We map those stacks as a single mandate rather than three disconnected workstreams.

A common assumption operators must correct

A common assumption is that a single offshore licence – or a registration in a jurisdiction perceived as lenient – is sufficient to serve clients in major financial markets globally. That assumption is incorrect and increasingly costly. The EU's MiCA regime, the FSRA's activity-based model and the FCA's financial-promotion rules each assert regulatory reach over activity directed at persons within their jurisdiction, regardless of where the operator is incorporated. An ADGM entity that markets acquiring services to EU merchants without a MiCA authorisation, or an offshore PSP that processes UK consumer payments without FCA registration, faces enforcement exposure in the destination jurisdiction that its home licence does not insulate it from.

The correct position is not that a business needs a licence in every jurisdiction where it operates – that is unworkable. The correct position is that the licence map must be built around the actual activity and the actual client base, not around the jurisdiction that was easiest to obtain. In our practice, we build that map at the structuring stage, before capital is deployed and before agreements are signed.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily because of perceived AML/CFT risk, insufficient compliance documentation or a business model they cannot map to their own risk appetite. A virtual-asset business that presents without a clear regulatory status, a credible compliance programme and documented transaction-monitoring procedures will be treated as high-risk. Holding a recognised licence – such as an FSRA authorisation in ADGM or a MiCA CASP in the EU – significantly improves the probability of a successful onboarding, but banks also conduct independent KYB reviews and may apply stricter internal thresholds than the regulator requires.

How can a VASP onboard with an EMI?

A VASP (virtual asset service provider) seeking to onboard with a regulated EMI (electronic money institution) must typically demonstrate regulatory status, a documented AML/CFT programme, a clean ownership structure and a business model the EMI can underwrite. EMIs regulated under MiCA or the UK's FCA framework are under their own regulatory obligation to conduct risk-based due diligence on business clients. Presenting the FSRA application file or an existing authorisation as part of the onboarding pack accelerates the EMI's KYB process and reduces the risk of rejection at the final compliance stage.

What does client-money safeguarding require?

Client-money safeguarding requires that funds held on behalf of clients or merchants are segregated from the operator's own funds, held in designated accounts at regulated credit institutions and reconciled on a defined schedule. Under the FSRA framework in ADGM, payment entities must implement safeguarding arrangements that reflect the regulator's expectations for the scale and risk of the business. Commingling client funds with operational funds is a regulatory breach, not merely an accounting issue. The acquiring agreement must document the specific account structure, the reconciliation frequency and the insolvency-ring-fencing mechanism the operator has in place.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and PSPs on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit, and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in payment-service and virtual-asset authorisation across ADGM, VARA and MiCA-aligned regimes.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours