For an early-stage crypto business, the gap between a registered entity and one that can actually move money is wider than most founders expect. A payment service provider agreement and an acquiring relationship are not administrative formalities. They are the fiat rails that determine whether your business can fund wallets, process card purchases, settle trades and pay out users. Without them, the entity exists on paper only.
Securing a PSP (payment service provider) agreement and an acquiring relationship as a crypto-native early-stage company is a structured legal and compliance process – not a sales conversation. The counterparty is a regulated institution that carries its own regulatory exposure for every client it onboards. Under the applicable AML (anti-money-laundering) and payments regimes across the EU, UK, UAE and Singapore, that institution must conduct enhanced due diligence on any VASP (virtual asset service provider) it serves. Understanding what that diligence looks at – before you submit an application – is the difference between a live account and a rejection that follows the business on every subsequent application.
This page sets out the regulated basis for PSP and acquiring agreements, the practical onboarding process for early-stage VASP founders, the common structural mistakes that cause rejections, the cross-border considerations that govern which rails are reachable, and a decision matrix to help founders identify the right sequencing.
The regulated basis for PSP and acquiring relationships
A payment institution or EMI (electronic money institution) that agrees to provide fiat rails to a VASP is extending a regulated service to a regulated counterparty. That creates a layered compliance obligation. The PSP must satisfy its own regulator that its VASP clients are themselves compliant. It must apply the Travel Rule (the obligation to pass originator and beneficiary data with a transfer) where it interacts with virtual asset transfers. And it must document the risk assessment of the relationship.
Under MiCA, the EU regulatory regime administered by ESMA and national competent authorities, the expectation is explicit: payment services touching crypto-asset service providers attract heightened scrutiny. The FCA in the United Kingdom applies the same logic through the Money Laundering Regulations, requiring registered cryptoasset businesses to demonstrate adequate controls before a regulated counterpart will onboard them. In Dubai, VARA's activity-based rulebooks impose equivalent obligations on licensed entities seeking banking or payment relationships.
For a founder, the practical consequence is this: a PSP or acquiring bank is not evaluating your business plan. It is evaluating your compliance posture, your beneficial-owner structure, your AML/KYC programme and the jurisdictional exposure of your user base. None of those questions have commercial answers. They have legal and structural answers.
What does an early-stage founder actually need from a PSP relationship?
An early-stage VASP typically needs three distinct functions from its payment relationships, and conflating them is a common structural error. The first is a settlement account – a fiat account into which exchange revenues, custody fees or token-sale proceeds can be received. The second is an acquiring agreement – an arrangement with a card acquirer that allows the business to accept Visa and Mastercard payments from users purchasing crypto. The third is a payout rail – the mechanism for returning fiat to users who sell or withdraw.
Each of these functions has a different regulatory footprint and a different counterparty risk profile. A settlement account may be provided by a correspondent bank, an EMI or a payments firm operating under a payment institution licence. An acquiring agreement requires a direct relationship with a card scheme participant who is willing to underwrite crypto merchant category risk. Payout rails involve either the same institution or a separate money-transfer operator.
In our practice, founders most commonly arrive at this stage having secured a VASP registration without having mapped which of these three functions their chosen PSP counterpart can actually provide. The mismatch – a licensed VASP with no route to card acquiring – is avoidable with the right sequencing.
To map the payment and acquiring stack for your build, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base geography and the banking – change the analysis materially.
The onboarding process: what a PSP due-diligence pack actually contains
PSP onboarding for a VASP is not a form-fill. It is a structured submission that mirrors a regulatory licence application in scope, if not in formality. Institutions conducting enhanced due diligence on a VASP counterparty will typically require documentation across five areas.
The first is corporate structure and beneficial ownership. A complete and verified corporate chart, UBO declarations to the applicable threshold and certified copies of constitutional documents are the minimum. Structures with nominee shareholders, multiple holding layers or offshore holding companies without demonstrated economic substance will trigger immediate escalation and, frequently, rejection.
The second is regulatory status. The PSP will require evidence of your VASP registration or licence, confirmation of the regulator's name and the specific activity authorised, and – increasingly – evidence of your MiCA transition pathway if you are operating in the EU. An expired registration, a registration in a jurisdiction not recognised by the PSP's compliance team, or a business operating in advance of registration will end the application.
The third is the AML/KYC programme. This means a written AML policy, a risk appetite statement, documented customer due-diligence procedures, a named compliance officer and evidence that the programme has been reviewed within the past twelve months. Institutions in major hubs – particularly those supervised by the FCA, MAS in Singapore or the FSRA in Abu Dhabi – will scrutinise this documentation with the same attention they apply to their own regulatory submissions.
The fourth is the business model and transaction profile. The PSP needs to understand what flows it will be processing: volumes by currency, average transaction size, the geographic distribution of your user base, and the asset classes involved. A business with a user base concentrated in high-risk jurisdictions, or one processing high-value transactions with retail users, presents a different underwriting case than a B2B settlements operator with institutional counterparties.
The fifth is source-of-funds documentation. Where the business is funded by token sales, VC investment or founder capital, the PSP will expect to trace the origin of that capital. This is not a request that can be met at the last stage of onboarding. It requires preparation from the funding round.
Why do early-stage applications fail – and what can be fixed?
Rejection at the PSP onboarding stage is not, in most cases, a verdict on the business. It is a verdict on the submission. In our cross-border practice, we see four structural reasons that account for the great majority of early-stage rejections.
The first is premature approach. Founders contact PSPs before the entity has a confirmed registration, before the compliance programme is written and before the corporate structure has been rationalised. A PSP's compliance team that receives an incomplete submission will decline it and note the application. A subsequent approach, even with a corrected submission, faces the residual reputational cost of the first contact.
The second is unresolved beneficial ownership complexity. Multi-jurisdictional holding structures, beneficial owners in high-risk countries, or UBOs who cannot provide verifiable source-of-wealth documentation are the single most common deal-breakers. Structures that were assembled for tax or operational reasons, without regard to the KYC exposure they create, routinely prevent onboarding.
The third is underestimated geographic risk. A VASP serving users in sanctioned jurisdictions, or operating without geographic restrictions, presents a compliance risk that most PSPs are unwilling to carry. The correct approach is a documented geoblocking policy and, where the business model requires it, a formal sanctions-screening programme that the PSP can review.
The fourth is wrong counterparty selection. Not all PSPs and EMIs will serve crypto businesses. Among those that will, there are significant differences in the asset classes they support, the jurisdictions they serve and the volumes they will underwrite at the early stage. Approaching the wrong counterpart wastes time and generates rejection records. Identifying the right institutions – those with an established crypto-client programme and supervisory approval to serve VASPs – is itself a research and positioning exercise.
A common assumption in this space is that a single offshore registration is sufficient to satisfy a PSP's compliance requirements globally. That assumption is incorrect. A PSP supervised by the FCA will require evidence of UK-equivalent controls regardless of where your entity is registered. MAS-supervised institutions apply the same logic under the Payment Services Act in Singapore. The requirement is substance, not just status.
The cross-border dimension: entity location versus rail location
For early-stage VASP founders, the gap between where the entity is registered and where its payment rails need to operate is a structural legal question, not an administrative one. A BVI-registered holding company may own the VASP operation, but it cannot itself hold a settlement account with an FCA-regulated EMI unless the EMI's compliance team is satisfied that the operating entity below the holding company carries the relevant registration and the AML programme. The rail follows the regulatory substance, not the corporate label.
Under the BVI VASP Act 2022, registration is available for virtual asset service providers operating from the BVI. But a BVI registration does not substitute for local authorisation where the payment counterparty – or the user base – is located in a regulated market. A founder operating a BVI-registered exchange with EU users will face MiCA obligations at the activity level, regardless of entity domicile.
The practical consequence of this is a multi-layer analysis. The entity that holds the PSP agreement needs to be the entity that carries the regulatory authorisation recognised by the PSP's home regulator. Where that creates a mismatch – for example, a Cayman-registered fund holding a VARA-licensed operating subsidiary seeking an EU EMI account – the structure requires legal mapping before the application is prepared.
We regularly advise founders on this mapping exercise. Operators we advise routinely discover that the entity their legal team formed for tax efficiency is not the entity that should hold the payment relationship, and that a restructure or a new regulated subsidiary is required before the PSP application can succeed.
Decision matrix: which PSP path fits your profile?
The right PSP and acquiring approach depends on the operator profile. The following four profiles represent the common early-stage configurations we encounter.
Profile A – Pre-revenue exchange with EU user base. A founder launching a crypto exchange targeting EU retail users, with a CASP authorisation in process under MiCA, should prioritise an EMI relationship with an institution that has existing crypto-client infrastructure in the EU and is comfortable with CASP applicants. The timeline for onboarding will be longer than for a licensed entity – typically several months – because the PSP will want to see the application status and the draft AML programme. The key risk is that the PSP declines to extend acquiring until full authorisation is granted, leaving card payments off the table at launch.
Profile B – B2B stablecoin settlement operator, Cayman-domiciled. A business using stablecoins for cross-border B2B settlements, with a CIMA registration and institutional counterparties only, presents a lower retail-risk profile. The acquiring question is less acute – there are no card payments – but the settlement account and payout rails require a PSP willing to handle USDT and USDC flows. Allied counsel in the relevant jurisdiction can identify the EMIs with the operational capability to process stablecoin-to-fiat conversions at the volume profile the business needs.
Profile C – Token issuance platform, Malta MFSA licensed. A token-issuance business transitioning from the prior VFA framework to MiCA CASP status under MFSA supervision has existing regulatory credentials but faces the transition uncertainty that PSPs are watching closely. The practical approach is to engage PSP counterparties that have existing relationships with MFSA-licensed entities and are familiar with the MiCA transition pathway. The risk is reputational: a disrupted onboarding mid-transition can delay the token sale calendar.
Profile D – Early-stage DeFi-adjacent platform, no current licence. A platform with some DeFi interface components and no current VASP registration is the hardest PSP onboarding case. Most PSPs with a crypto programme will not onboard an unlicensed entity. The correct first step is to determine whether the activity triggers a licensing obligation – a legal analysis that turns on the functions the platform performs, not the label it uses – and to obtain the relevant registration before approaching PSP counterparties.
Structuring the application for success
In our experience, the founders who secure PSP and acquiring agreements quickly are not those with the simplest businesses. They are those who have prepared their legal and compliance posture before they initiate the conversation with a payment institution.
Preparation has four components. First, a clean corporate structure with verified UBOs and documented source of wealth. Second, a current regulatory registration with the scope that matches the business model. Third, a written AML/KYC programme that has been reviewed and signed off by the named compliance officer. Fourth, a transaction profile document that describes expected volumes, geographies, asset classes and average transaction sizes in concrete terms.
In a recent matter, an early-stage exchange operator had approached three EMIs and been rejected each time. The rejections were not communicated with reasons – PSPs rarely provide them. We conducted a structural review and identified two issues: a holding-company layer in a jurisdiction flagged by the PSP's risk matrix, and an AML policy that described a transaction-monitoring regime the business had not yet implemented. Resolving those two issues – through a corporate restructure and a revised compliance programme – allowed the business to re-approach a suitable counterparty with a materially stronger submission. The onboarding was completed within a few months of the revised approach.
If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Write to OBOLUS at info@oboluslaw.com.
Self-assessment checklist before approaching a PSP
Before initiating contact with a payment service provider or card acquirer, an early-stage founder should be able to answer yes to each of the following questions.
- Is the entity that will hold the PSP agreement the same entity that holds (or is applying for) the relevant VASP registration?
- Are all beneficial owners identified, verified and able to document source of wealth?
- Is a written AML/KYC policy in place and reviewed within the past twelve months?
- Is a named compliance officer appointed and documented?
- Is a geographic restrictions policy in place, with sanctions-screening coverage?
- Is the transaction profile documented (volumes, currencies, asset classes, user geographies)?
- Has the PSP counterpart been selected on the basis of its known crypto-client programme, not just availability?
- Has the holding-company structure been reviewed for jurisdictional risk from the PSP's perspective?
A no answer on any of the above does not prevent an application. It signals a preparation gap that is better closed before approach than discovered in due diligence.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital-Asset Businesses – the full practice overview covering fiat rails, EMI relationships and banking strategy for VASPs across major hubs.
- Payment Institution Licensing for Established Operators – analysis of PI licence routes for businesses scaling beyond EMI onboarding into direct authorisation.
- PSP and Acquiring Agreement for Regulated Entities – the counterpart service page covering PSP negotiation for entities that already hold a full licence.
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because of unresolved compliance exposure rather than a general policy against digital assets. The most common triggers are an incomplete or outdated AML/KYC programme, beneficial ownership structures the bank cannot verify, a user base with significant exposure to high-risk or sanctioned jurisdictions, or a transaction profile that differs materially from what was disclosed at onboarding. Rectifying the underlying structural issue – and demonstrating the correction to a new banking counterpart – is the operative step.
How can a VASP onboard with an EMI?
A VASP seeking an EMI relationship must prepare a submission that satisfies the EMI's enhanced due-diligence process. That means a verified corporate structure with documented UBOs, a current VASP registration, a written AML/KYC programme, a named compliance officer and a documented transaction profile. The EMI will assess its own regulatory exposure under the applicable AML regime – MiCA and national rules in the EU, the Money Laundering Regulations in the UK, or the Payment Services Act in Singapore – before accepting a VASP as a client. Matching the right EMI to the VASP's profile and jurisdiction is as important as the documentation itself.
What does client-money safeguarding require?
Client-money safeguarding requires a licensed payment institution or EMI to hold funds received from clients in a segregated account, separate from the firm's own money, at an approved credit institution or in qualifying assets. The applicable regime – whether MiCA, the UK Payment Services Regulations or an equivalent national framework – sets the specific requirements for segregation, reconciliation frequency and insolvency protection. For a VASP relying on an EMI for fiat custody, the PSP agreement should explicitly address how client funds are held and what protections apply in the event of the EMI's insolvency.
OBOLUS is an independent digital-asset law boutique acting exclusively for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than seventy jurisdictions, on disputes and on-chain asset recovery across more than twenty-five forums, and on the tax, banking and compliance structures that sit around them. Digital assets are the whole of our practice. We map the licence, banking and payment stack across operating, custody and payment layers before you commit – so that the structure you build is one that payment counterparties will accept. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory and Compliance Analyst – specialises in VASP licensing frameworks and payment institution compliance for early-stage digital-asset businesses across the EU, UK and Gulf hubs.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.