EST · MMXXVI
Home/Jurisdictions/United Kingdom/PSP and acquiring agreement in United Kingdom
Banking, Payments & EMI Onboarding

PSP and acquiring agreement in United Kingdom

Psp and acquiring agreement in United Kingdom. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Securing fiat rails for a digital-asset business in the United Kingdom is one of the most commercially decisive steps an operator can take – and one of the most frequently mishandled. A payment service provider (PSP) agreement governs the mechanics of accepting and sending money on behalf of customers; an acquiring agreement is the contract with the acquiring bank or institution that settles card or direct-debit transactions into a merchant's account. For a crypto exchange, a custodian or a token-issuance platform, both instruments sit at the intersection of the Financial Conduct Authority (FCA) regulatory perimeter and the contractual risk appetite of the counterparty institution. Get either wrong and the entire operating model stalls.

The United Kingdom imposes a layered regime on payment services and on digital-asset activity alike. Under the FCA's supervision, any business that accepts funds, settles transactions or holds client money in connection with a regulated payment service must hold – or rely on an exemption from – authorisation or registration under the applicable payment-services rules. Separately, any crypto-asset business operating in or into the UK must be registered with the FCA for anti-money-laundering purposes under the Money Laundering Regulations. These two requirements frequently overlap for businesses that combine a payment function with a crypto-asset activity. Failing to understand both is the source of most onboarding failures we see in practice.

This page sets out the regulatory basis for PSP and acquiring relationships in the UK, the practical process for onboarding with a UK-regulated institution, the cross-border realities for inbound operators, and the decision points that determine whether a direct or intermediated banking structure is appropriate for your business.

The UK regulatory perimeter for payment services

The FCA is the competent authority for payment services, e-money issuance and crypto-asset AML registration in the UK, and each function requires a distinct permission. Payment institutions operating in the UK must be either fully authorised or registered as a small payment institution, depending on transaction volumes and business scope. E-money institutions (EMIs) – entities that issue prepaid electronic money – hold a separate authorisation, and an EMI permission is often the instrument that allows a business to hold client balances and issue accounts. A business that wishes to accept card payments through an acquiring bank must have in place either its own FCA authorisation in the relevant payment-services category or a contractual arrangement with an authorised acquirer that onboards it as a sub-merchant.

The distinction between a payment institution and an e-money institution matters commercially. An EMI can hold client funds in a float and issue electronic money redeemable against that float. A payment institution executes payment transactions but typically cannot hold client money between instructions in the same way. For a crypto-asset business that wants to offer fiat-in, fiat-out functionality, the EMI model is usually the more flexible instrument. In our practice, we regularly advise operators who arrive assuming that a payment-institution registration is sufficient, only to discover that their intended product – for example, maintaining a fiat balance a user can top up and draw down at will – requires the broader EMI authorisation.

Crypto-asset businesses seeking PSP or acquiring relationships must also hold, or be working toward, FCA crypto-asset registration under the Money Laundering Regulations. UK-regulated PSPs and acquirers conduct their own due diligence on merchant counterparties; an applicant that cannot demonstrate FCA registration – or a clear path to it – will be declined at underwriting. The FCA's registration process is distinct from a payment-services authorisation, but both are prerequisites in the eyes of most UK-regulated financial institutions.

The Travel Rule – the obligation to pass originator and beneficiary data with a transfer – also applies to UK VASPs under FCA guidance, and a PSP's compliance team will frequently ask for evidence of Travel-Rule compliance before proceeding. Demonstrating that evidence early accelerates the onboarding timeline materially.

Why do UK PSPs and acquirers decline crypto merchants?

UK-regulated payment institutions and acquiring banks decline crypto-merchant applications primarily on risk-appetite and compliance grounds, not because crypto-asset activity is inherently impermissible. The FCA framework does not prohibit a payment institution from serving a crypto business; it requires the institution to conduct proportionate due-diligence and to satisfy its own AML/CFT obligations when doing so. The practical effect is that each institution sets an internal risk threshold, and crypto-asset businesses frequently fall outside it.

The most common grounds for refusal are: absence of FCA crypto-asset registration or a credible timeline to obtain it; unclear business-model documentation; jurisdictional mismatch (the entity is incorporated offshore but users are primarily UK-resident); and inadequate AML-programme documentation. We have seen applications declined within days on each of these grounds, after weeks of preparation by the applicant.

A secondary driver is chargeback exposure. Acquiring banks price merchant risk in part on expected chargeback rates. Crypto transactions – particularly those involving token purchases that customers later dispute – generate chargeback patterns that acquirers treat as elevated. An operator that cannot demonstrate contractual controls on its customer-facing terms, a clear refund policy and a chargeback-management process will find acquiring agreements difficult to close regardless of its regulatory status.

The instinct to resolve these problems by routing through an offshore entity is understandable but usually counterproductive. A UK-resident user base, a UK-facing website or a UK-incorporated operating entity each engage the FCA perimeter independently. Structuring the payment layer through a non-UK vehicle while retaining UK commercial substance does not displace the regulatory obligation; it adds a cross-border compliance burden without removing the UK one. A common assumption is that a single offshore licence is sufficient to serve a global customer base, including UK customers. It is not. The FCA applies the regime by reference to where service is provided and received, not only by reference to where the entity is incorporated.

What does the onboarding process look like for a crypto business with a UK PSP?

Onboarding a crypto-asset business with a UK PSP or acquirer follows a structured due-diligence sequence that typically spans several weeks from first engagement to account activation. The process is more demanding than standard merchant onboarding, and the preparation phase is where most applications succeed or fail.

The first stage is regulatory documentation. The PSP's compliance team will require evidence of FCA registration or authorisation, corporate structure charts, beneficial-ownership disclosure down to the natural-person level, AML/CFT policy documentation, and – for crypto-native businesses – a written description of the token types handled, the wallet architecture, and the on-chain compliance controls in place. Where the business is incorporated outside the UK but targets UK users, the PSP will also ask for a legal analysis of the regulatory basis on which the UK-facing activity is conducted.

The second stage is commercial underwriting. The acquirer or PSP assesses transaction volumes, average transaction values, the geographic distribution of the customer base, and the expected chargeback profile. This stage often stalls because applicants submit projected figures without underlying commercial evidence. In our cross-border practice, we regularly advise clients to prepare a structured business-model memorandum at the outset – a document that pre-empts underwriting questions rather than answering them reactively.

The third stage is legal review of the PSP or acquiring agreement itself. These agreements are rarely negotiated to any significant degree for standard merchant relationships, but for larger-volume or structurally complex businesses, the terms on reserve requirements, settlement delays, termination rights and liability caps merit close review. Reserve requirements in particular – the cash the PSP holds back against potential chargebacks – can represent a material working-capital constraint if accepted without negotiation.

The fourth stage is ongoing compliance. UK PSPs are under continuous FCA supervision and pass that obligation downstream. Merchants should expect periodic requests for updated AML documentation, changes-in-business notifications, and – in some cases – transaction-level reporting. Operators that treat onboarding as a one-time event, rather than the beginning of a compliance relationship, tend to face account-suspension risk when a routine review discloses a change they did not proactively report.

For a scoped assessment of your PSP and acquiring onboarding position in the UK, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user geography, the token types – change the analysis. We map the full picture before you approach a counterparty.

What is the cross-border reality for inbound operators seeking UK fiat rails?

An operator incorporated in the EU, the BVI, the Cayman Islands or another offshore jurisdiction and seeking UK fiat access faces a structurally different set of questions from a UK-incorporated business. The threshold question is whether the business has – or will have – sufficient UK commercial substance to engage the FCA perimeter directly. If it does, UK regulatory compliance is unavoidable. If it does not, the question becomes how to access UK payment infrastructure through a correspondent or intermediated structure without inadvertently triggering UK regulatory obligations.

Under the MiCA regime now in force across the EU, a CASP (crypto-asset service provider) authorised in an EU member state and passporting into the EEA does not automatically acquire UK market access. Post-Brexit, the UK and EU operate parallel regimes without a reciprocal-recognition arrangement for crypto-asset services. A business that holds a Lithuanian or Maltese CASP authorisation under MiCA must obtain its own FCA registration for UK-resident users, or must structure its product to fall clearly outside the UK perimeter.

In practice, many operators serving UK and EU users simultaneously maintain two regulatory relationships: an FCA-registered or FCA-authorised entity for UK activity and an EU-licensed entity for EEA activity. The payment architecture then runs through separate EMI counterparties in each jurisdiction – a UK-regulated EMI for sterling settlements and an EU-regulated EMI for euro settlements. This is structurally efficient but requires clear contractual demarcation of which entity serves which user base, and it requires the operator's AML programme to cover both jurisdictions without creating gaps at the boundary.

For operators seated in ADGM (under the FSRA regime) or in VARA-regulated Dubai, accessing UK fiat rails typically requires the establishment of a UK-registered entity or the engagement of a UK-regulated payment institution willing to onboard a VARA or FSRA-regulated counterparty. We regularly work alongside allied counsel in the relevant jurisdiction to coordinate the regulatory posture across both ends of this structure. The UK institution's compliance team will invariably ask for a legal opinion on the regulatory status of the offshore entity; preparing that opinion in advance shortens the onboarding timeline by a material degree.

How does client-money safeguarding work under the UK regime?

Client-money safeguarding is a regulatory requirement imposed on UK-authorised payment institutions and EMIs, and it directly affects the contractual architecture of any PSP or acquiring arrangement in which the institution holds client funds. The obligation requires an authorised institution to segregate funds held on behalf of payment-service users from the institution's own funds, and to maintain those funds in a safeguarding account or in qualifying insurance or guarantee arrangements.

For a crypto-asset operator that holds fiat on behalf of users – for example, a fiat wallet from which users fund token purchases – the safeguarding obligation determines the structural design of the holding arrangement. If the operator itself is an FCA-authorised EMI, the obligation rests on the operator. If the operator relies on a third-party EMI to hold user fiat, the obligation rests on that EMI, but the operator bears contractual exposure if the EMI fails to comply and user funds are lost.

The practical consequence is that the PSP or EMI agreement must be reviewed not only for commercial terms but for the allocation of safeguarding responsibility. Agreements that pass safeguarding obligations to the merchant, or that are ambiguous about which entity holds user funds and on what basis, create regulatory risk for both parties. We have seen operators enter EMI agreements that were commercially straightforward but structurally problematic because the safeguarding architecture was inconsistent with the operator's own product description to users.

In a recent onboarding matter, a payments-adjacent crypto business sought to launch a fiat-wallet product in the UK and engaged a third-party EMI as its banking partner. The EMI agreement allocated client-money liability to the operator in terms that were inconsistent with the operator's consumer-facing terms. We identified the conflict during legal review, negotiated a revised allocation clause, and the product launched without the operator carrying an unintended safeguarding exposure. The matter closed within a standard onboarding window.

How do tax and banking considerations interact with a UK PSP structure?

The tax analysis for a UK PSP or acquiring structure runs in parallel to the regulatory analysis, and the two frequently intersect in ways that create unexpected cost. A UK-incorporated entity that holds an FCA registration and enters a PSP agreement is a UK tax resident for most purposes; its profits, including any spread income or transaction fees, will be subject to UK corporation tax at the prevailing rate. An operator that structures its UK activity through a branch of an offshore entity, rather than through a UK subsidiary, faces a different permanent-establishment analysis, with corresponding withholding and transfer-pricing considerations.

VAT treatment of payment and crypto-asset services in the UK is a distinct area of complexity. The FCA's post-Brexit rules on crypto-asset promotion interact with HMRC's treatment of crypto-asset transactions; the VAT position on payment-service fees charged to crypto businesses is not always straightforward, particularly where the underlying transaction involves a token that HMRC classifies differently from a straightforward payment instrument. We advise operators to obtain a written VAT analysis before pricing their PSP fees into a business model, because a mistaken VAT assumption can alter unit economics materially.

Banking itself – the maintenance of a corporate current account – is a prerequisite to any PSP or acquiring relationship. UK banks are notoriously cautious about onboarding crypto-asset businesses, and many operators find that obtaining a corporate account takes longer, and is more documentation-intensive, than obtaining the regulatory registration that the bank uses as a prerequisite. The sequencing problem – the bank wants the FCA registration; the FCA registration process assumes a banking address – is a real obstacle in practice. The practical resolution is to secure an interim account with a UK-regulated EMI that does onboard crypto businesses, use that address and account for the FCA application, and transition to a full banking relationship post-registration.

Which PSP and acquiring structure fits which operator profile?

The right structure depends on the operator's licensing position, user geography, product design and risk appetite. Three common profiles illustrate the decision logic.

An EU-licensed CASP (authorised in the EU under MiCA, seeking UK access for a sterling user base) should establish a UK-registered entity and obtain FCA crypto-asset registration before approaching a UK PSP. The EU licence does not transfer. The UK entity then onboards with a UK-regulated EMI for client-money holding and a separate acquirer for card settlements. The cross-border structure requires a clear legal boundary between the EU and UK user bases and a transfer-pricing arrangement between the two entities. The key risk at this stage is that the FCA registration timeline – which varies and cannot be guaranteed – delays market entry.

A UAE-based operator (VARA or FSRA-regulated, with a minority of UK-resident users) should obtain specific UK regulatory advice on whether its UK user activity crosses the FCA perimeter threshold. If it does, the operator needs either FCA registration or a restructured product that clearly excludes UK-resident users. If the UK user base is commercially significant, establishing a UK entity and seeking FCA registration is typically the more sustainable path. The PSP onboarding then follows the standard process described above. The key risk is underestimating the FCA's own timeline for review.

A UK-incorporated crypto exchange (seeking to add card-acquiring capability to an existing FCA-registered business) is the most straightforward profile. The operator already holds FCA registration; the question is selecting the right acquiring partner and negotiating the reserve and settlement terms. The key risk for this profile is chargeback exposure, which can be managed contractually but requires proactive engagement at the underwriting stage.

If a prior PSP application stalled or an account was closed, a second read of your regulatory and commercial position can identify the structural reason and the route forward. Contact OBOLUS at info@oboluslaw.com.

FAQ

Why do banks close crypto company accounts?

UK banks close crypto-company accounts most often because the business fails to maintain the ongoing compliance documentation the bank requires or because the bank's risk appetite shifts following an internal review. The immediate triggers include: failure to disclose a material change in business activity, a volume spike that falls outside the profile presented at onboarding, or a regulatory development that moves the business into a category the bank has decided to exit. FCA crypto-asset registration is a necessary condition, but it does not guarantee account retention; the contractual relationship sits above the regulatory floor and the bank retains broad contractual termination rights.

How can a VASP onboard with an EMI?

A VASP (virtual asset service provider) seeking to onboard with a UK-regulated EMI should prepare a structured due-diligence package before making first contact. That package should include: corporate structure and beneficial-ownership charts, evidence of FCA crypto-asset registration (or a clear timeline to it), a written AML/CFT policy aligned with FATF Recommendation 15 standards, a description of Travel Rule compliance arrangements, and a business-model memorandum setting out transaction volumes, user geography and token types. EMIs with established crypto-business onboarding programmes typically respond more quickly to applications that pre-empt their standard questionnaire.

What does client-money safeguarding require?

Client-money safeguarding under the UK payment-services regime requires an authorised payment institution or EMI to hold funds received from payment-service users separately from the institution's own funds. In practice, this means maintaining a designated safeguarding account with a credit institution, or holding qualifying insurance against the relevant exposure. For a crypto operator that relies on a third-party EMI to hold user fiat balances, the safeguarding obligation rests on the EMI, but the operator should confirm in its agreement that the EMI's safeguarding arrangements cover the operator's user funds specifically, and should understand the contractual consequences if the EMI becomes insolvent.

About OBOLUS

OBOLUS is an independent digital-asset law boutique acting exclusively for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than 70 jurisdictions, on disputes and on-chain asset recovery across more than 25 forums, and on the tax, banking and compliance that sit around those activities. Digital assets are the whole of our practice. We map the licence, banking and payment stack across operating, custody and payment layers before you commit to a structure – so the regulatory and commercial decisions are made together, not sequentially. We work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications where that is needed. To discuss your situation, contact info@oboluslaw.com or reach us via t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in FCA perimeter analysis and payment-services regulatory structures for cross-border digital-asset operators.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours