EST · MMXXVI
Home/Services/Banking Payments Emi/PSP and acquiring agreement for Established Operators
Banking, Payments & EMI Onboarding

PSP and acquiring agreement for Established Operators

Psp and acquiring agreement for Established Operators. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOL

Established crypto operators – exchanges, custodians and token issuers that already hold a VASP (virtual asset service provider) licence – routinely discover that a regulatory approval is only the first gate. The harder gate is securing a PSP and acquiring agreement (a contract with a payment service provider or card acquirer that carries fiat flows on behalf of the business) and the banking rails behind it. Without those rails, a licensed operator cannot fund wallets, accept card payments or pay out withdrawals. The legal and commercial work required to close that gap is the subject of this page.

For an established operator, the risk is acute. Losing a PSP relationship mid-operation can freeze client funds, breach licence conditions and trigger regulatory scrutiny – all simultaneously. We regularly advise operators at precisely this inflection point, and the pattern is consistent: the structural choices made at the licence stage either open or close the door to quality banking partners later.

This page explains the regulated basis for PSP and acquiring relationships in a digital-asset context, the process for securing and maintaining them, the cross-border complications that arise when the entity, the users and the bank sit in different jurisdictions, and the decision matrix that should frame every operator's approach.

What is the regulated basis for a PSP and acquiring relationship?

A payment service provider agreement is a contract under which a licensed payment institution or EMI (electronic money institution) agrees to process fiat transactions for the operator's business. An acquiring agreement is the specific instrument through which a card acquirer settles card-funded transactions – typically card top-ups to a crypto exchange or purchases of tokens. Both sit within a regulated perimeter. In the EU and EEA, that perimeter is set by the Payment Services Directive regime and, for e-money issuance, the Electronic Money Directive; in the UK, by the FCA's payment services framework; in Singapore, by the Payment Services Act administered by MAS; and across the Gulf, by VARA, FSRA and the Central Bank of the UAE respectively.

The regulated nature of the counterparty matters. An EMI or payment institution that takes on a crypto-business client becomes exposed to the AML risk profile of that client. Regulators in every leading hub now expect payment firms to conduct thorough due diligence on crypto business customers – applying, in substance, the same Travel Rule (the obligation to pass originator and beneficiary data with each transfer) and enhanced due diligence obligations that apply to the crypto firm itself. That regulatory mirror image is what makes onboarding both slow and structurally sensitive.

The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. For a scoped assessment of your PSP and acquiring position, contact OBOLUS at info@oboluslaw.com.

Why do established operators face a higher bar than start-ups?

Counter-intuitively, an established operator often faces a more demanding due diligence process than a pre-revenue applicant, because the PSP can now see real transaction volumes, an actual user geography and a live compliance record. Each of those is an underwriting variable.

A start-up presents a clean compliance slate and a low initial risk exposure. An operator processing meaningful volumes presents a PSP with a live book of business that its compliance and financial-crime teams must underwrite in detail. That underwriting covers the operator's AML programme, its sanctions screening, its chargeback history if card payments are in scope, its KYC coverage rate and the quality of its Travel Rule tooling. In our practice, the single most common reason an established operator's PSP application stalls is an incomplete or inconsistent compliance manual – not the business model.

A second factor is geography. An operator licensed in, say, the AIFC under the Astana Financial Services Authority (AFSA) but serving users across Europe, the Middle East and Southeast Asia presents a multi-jurisdictional risk profile that a single PSP may not be willing or structurally able to absorb. Understanding which payment relationship sits at which layer – and which entity bears the regulated activity in each geography – is the structural question that drives this work.

What do PSPs and acquirers actually assess in a crypto business?

The due diligence a PSP or acquirer performs on a crypto-business applicant tracks closely to the risk categories its own regulator examines on inspection. In our cross-border practice, we have seen the following categories consistently determine outcomes.

  • Licence validity and scope: Is the VASP or CASP authorisation current, and does the licensed activity cover what the business actually does? A custody licence does not authorise exchange activity; a broker licence does not authorise wallet issuance. Mismatches between the licence scope and the actual product are an immediate red flag for a prospective PSP.
  • AML/KYC programme quality: The PSP's own AML obligations under FATF Recommendation 15 require it to treat a crypto-business customer as a higher-risk category. It will want to see documented policies, an independent audit, evidence of Travel Rule implementation and a named Money Laundering Reporting Officer.
  • Chargeback and fraud rates: For acquiring specifically, card network rules impose chargeback thresholds. Crypto businesses historically carry elevated chargeback rates due to consumer-dispute patterns. An acquirer will want historical data and a mitigation plan.
  • Source-of-funds documentation: PSPs increasingly require a corporate source-of-funds analysis covering the operator's own capitalisation – not just that of its end customers.
  • Sanctions and PEP exposure: The operator's beneficial ownership structure, the jurisdictions from which it accepts users, and the currencies it settles all carry sanctions implications. A PSP serving an operator with material exposure to sanctioned geographies risks secondary liability under OFAC, OFSI or EU sanctions regimes.

Operators we advise routinely underestimate the depth of this review. A well-structured PSP application should anticipate every one of these categories and provide responsive documentation before the PSP asks.

How do cross-border structural decisions affect banking access?

The cross-border reality of digital-asset business is that the operating entity, the users, the custodied assets and the banking partner rarely sit in the same jurisdiction. That fragmentation creates legal and commercial friction at every layer.

Consider a common structure: a Malta-licensed operator under the MFSA framework – transitioning to CASP (Crypto-Asset Service Provider) authorisation under MiCA – serving users across the EU and holding reserves with a bank in an EEA jurisdiction. The operator's payment flows may need to run through an EU-licensed EMI to benefit from passporting. If card acquiring is required, the acquirer must be licensed to process in each jurisdiction where card-funded transactions originate. A BVI or Cayman holding structure above the operating entity introduces an additional beneficial ownership analysis for every bank and PSP in the chain.

Under MiCA, the CASP authorisation passports across the EU and EEA – but passporting the licence does not automatically passport the payment relationship. The EMI or payment institution servicing the CASP may itself require a separate regulatory analysis of the activity it is facilitating in each member state. We map this layer by layer before any application is submitted.

A parallel complexity arises in the UAE. VARA regulates mainland Dubai; the DIFC and ADGM are separate financial free zones with their own frameworks under the FSRA. An operator holding a VARA licence cannot assume that an ADGM-licensed payment firm will onboard it without additional structuring work – and the Central Bank of the UAE has its own oversight remit for fiat payment flows that crosses both perimeters.

For businesses building between two hubs – say, a Singapore MAS-licensed Digital Payment Token (DPT) service that also wants EU fiat rails – the structural question is whether a single EMI relationship can serve both geographies or whether parallel payment structures are required. In our experience, a single-entity approach only works when the EMI holds the relevant permissions in both regions. The alternative is a two-entity structure with transfer-pricing and tax implications that must be resolved before banking is approached.

If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Write to OBOLUS at info@oboluslaw.com.

What does the PSP and acquiring onboarding process look like in practice?

The onboarding process for a PSP or acquiring relationship follows a broadly predictable sequence, but the duration and complexity at each step vary considerably by institution, jurisdiction and operator profile.

Step 1: Readiness audit. Before approaching any PSP, an established operator should conduct a compliance readiness audit against the PSP's likely due diligence checklist. This covers licence status, AML policy documentation, KYC coverage, Travel Rule tooling, corporate structure and source-of-funds analysis. Operators who skip this step and submit incomplete packages typically receive a request-for-information response that delays the process by weeks.

Step 2: PSP identification and pre-qualification. Not every PSP serves crypto businesses. The universe of willing counterparties is smaller than the overall payment-institution population, and within that subset, individual PSPs have specific risk appetites by product type, geography and volume tier. Identifying the right counterparties – and qualifying the operator's profile against their intake criteria – is a material step that legal counsel can accelerate.

Step 3: Application and package assembly. The formal application package typically includes the operator's regulated entity details, its licensed activities, its compliance programme documentation, its corporate structure chart, beneficial ownership information, financial projections and a proposed flow-of-funds diagram. For acquiring specifically, historical chargeback data and a fraud-mitigation plan are standard requirements.

Step 4: Legal review of the agreement. A PSP agreement and an acquiring agreement each contain terms that bear directly on the operator's regulatory position. Indemnity provisions, termination triggers, reserve-account requirements and liability caps all require careful review. The agreement should be read against the operator's own licence conditions to confirm that no term of the payment contract puts the operator in breach of its regulatory obligations. We have seen acquiring agreements that impose blanket prohibitions on chargebacks that conflict with the operator's consumer-protection obligations under its own licence.

Step 5: Negotiation and execution. PSPs and acquirers present standard-form agreements. For a well-capitalised established operator, meaningful negotiation is achievable on key commercial and legal terms – including reserve-account levels, settlement cycles and the conditions under which the PSP may suspend the relationship. These terms matter operationally: a PSP that can suspend on forty-eight hours' notice with no cure period creates a material business risk.

Step 6: Ongoing compliance monitoring. A PSP relationship does not end at execution. The PSP will conduct periodic reviews of the operator's compliance posture, and most agreements include a right to request updated compliance documentation on reasonable notice. Operators that allow their AML programme documentation to fall out of date risk triggering a PSP review that results in suspension.

What are the most common mistakes established operators make?

A recurring pattern in the matters we handle is that established operators – businesses with genuine compliance infrastructure – lose banking relationships not because of regulatory failure, but because of avoidable process and structural errors. The following represent the categories we encounter most frequently.

Relying on a single banking or PSP relationship. Concentration risk is a systemic vulnerability. An operator with a single PSP relationship has a single point of failure. When that relationship is terminated – often with short notice, for reasons the PSP will not fully disclose – the operator has no fallback. Diversification across at least two payment relationships, ideally in different jurisdictions, is a structural precaution that most operators delay until after their first termination.

Treating the PSP relationship as a commercial matter rather than a regulatory one. A common assumption is that PSP onboarding is a sales or business-development process and that legal counsel is only needed if something goes wrong. In practice, the due diligence a PSP conducts is substantively legal. The documents it reviews – AML policies, sanctions screening procedures, corporate authorisations – are legal instruments. Presenting them without legal preparation produces gaps that trigger extended review or rejection.

Failing to align the licence scope with the payment flow. We regularly see operators whose payment flows do not map cleanly to their licensed activities. An operator licensed to provide custody services that also processes exchange transactions through the same entity may be operating outside its licensed scope – a finding that a PSP's compliance team will identify and that may result in either rejection or a requirement to restructure before onboarding.

Underestimating the contractual risk in termination clauses. PSP agreement termination provisions vary widely. Some grant the PSP termination rights on notice with no fault required; others allow suspension of the payment flow while a compliance review is conducted, with no obligation to complete that review within any specified period. Operators that accept these terms without negotiation expose themselves to the operational equivalent of an injunction – their fiat rails frozen by contract rather than by court order.

In a recent matter, an exchange operator sought to onboard a new acquirer after its incumbent relationship was terminated following a compliance review. The operator's AML programme was substantively sound, but the programme documentation had not been updated since the original licence application. We coordinated a rapid documentation refresh, prepared a responsive package and managed the new acquirer's due diligence process. The operator secured a replacement relationship within the timeframe required to maintain service continuity.

How should an established operator choose its PSP and acquiring structure?

The right structure depends on the operator's product, its user geography, its licence stack and its operational risk tolerance. The following profiles describe the most common configurations we encounter and the considerations that apply to each.

Profile A: EU-licensed CASP under MiCA, serving EU retail and institutional users. The natural payment architecture is an EU-licensed EMI providing e-money accounts and SEPA access, with a card acquirer that holds EU acquiring permissions. The CASP passporting right covers the licensed activity; the EMI's passporting right covers the payment service. Aligning the two requires confirming that the EMI is willing and permitted to service a CASP customer in each relevant member state. The principal risk is that the EMI's own regulator may impose conditions on crypto-business onboarding that create an operational overhead for the operator. Timeline to a functional payment relationship typically runs to several months from initial approach, subject to documentation readiness.

Profile B: UAE (VARA-licensed) operator serving the Middle East and seeking card acquiring. VARA-licensed operators require payment relationships that are compatible with both the VARA regime and the Central Bank of the UAE's oversight of fiat flows. Card acquiring for a UAE-based exchange requires an acquirer with Gulf presence and card-network permissions in the relevant markets. Cross-border card flows – particularly for users in GCC jurisdictions – require analysis of each country's payment regulation. ADGM-based operators face an additional layer because the FSRA framework under ADGM is distinct from VARA. Allied counsel in the relevant jurisdiction should be engaged for the local payment-regulation analysis.

Profile C: Multi-jurisdiction operator with a Singapore MAS licence and EU ambitions. A Singapore DPT service seeking EU card acquiring or SEPA access will generally need a separate EU-licensed entity to carry the CASP authorisation required under MiCA and to serve as the contracting party for the EU payment relationship. The alternative – routing EU fiat flows through the Singapore entity – requires careful analysis of the payment services regulations in each EU member state where users are located and is likely to require either a direct MiCA CASP authorisation or a passporting arrangement from an EU-licensed group entity. The tax and transfer-pricing implications of a two-entity structure should be modelled before the banking structure is finalised.

Profile D: Offshore-structured operator (BVI or Cayman holding, operating subsidiary in a licensing hub) seeking global PSP coverage. The offshore holding layer introduces beneficial ownership complexity that every PSP and acquirer in the chain must work through. Providing clear, consistent beneficial ownership documentation across the group structure, and ensuring that the operating subsidiary – not the holding company – is the contracting party for each payment relationship, is the baseline structural requirement. We map the licence stack across operating, custody and payment layers before any application is submitted, to ensure that the entity presented to the PSP is the right one.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily because the operator's AML and compliance documentation does not meet the bank's own regulatory obligations. Under FATF Recommendation 15, financial institutions must treat virtual-asset businesses as higher-risk customers and apply enhanced due diligence. When a bank cannot satisfy itself that the operator's AML programme, sanctions screening and beneficial ownership are adequately documented, the path of least regulatory resistance is account closure. Structural issues – an offshore holding entity, an unclear licence scope or a mismatch between the licensed activity and the actual product – accelerate that decision. Proactive compliance documentation and pre-application legal preparation materially reduce this risk.

How can a VASP onboard with an EMI?

A VASP seeking to onboard with an EMI must present the EMI's compliance team with documentation that satisfies the EMI's own regulatory obligations. That typically includes the VASP's licence certificate and scope, its AML/KYC programme documentation, evidence of Travel Rule implementation, a corporate structure chart with beneficial ownership, a source-of-funds analysis and financial projections. The EMI will assess the VASP's risk profile against its own risk appetite. In jurisdictions where VASP onboarding is specifically regulated – such as under MiCA's CASP regime – the EMI may also require confirmation that the VASP's licensed activities align with the payment services the EMI is being asked to provide. Preparation and pre-qualification are the primary drivers of a successful outcome.

What does client-money safeguarding require?

Client-money safeguarding requires an operator to hold client fiat balances separately from its own funds and to ensure that those balances are protected in the event of the operator's insolvency. Under EMI regimes across the EU, the UK and Singapore, safeguarding typically requires either depositing client funds in a designated account at a credit institution or holding qualifying liquid assets of equivalent value. The specific requirements – the eligible institution types, the account designation formalities and the reconciliation frequency – vary by jurisdiction and licence category. Failure to meet safeguarding obligations is one of the most commonly cited grounds for regulatory action against payment firms and is a key due diligence criterion for any PSP reviewing a crypto-business applicant.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, custody and payment stack before you commit – so the structure that reaches the bank is the one that stays there. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when payment relationships break down and assets are at risk. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in PSP onboarding, VASP regulatory compliance and cross-border payment structure analysis for digital-asset operators.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours