For an institutional operator building a digital-asset business, the moment a payment service provider (PSP) or acquiring relationship falls through is the moment revenue stops. A single terminated agreement can freeze card processing, strand client funds and trigger a cascade of counterparty reviews that takes months to unwind. The legal question is not simply "how do we get a bank account" – it is how to construct a payment and acquiring architecture that survives regulatory scrutiny on both sides of the relationship, across multiple jurisdictions, at scale.
A PSP and acquiring agreement ban – the formal or informal refusal by a payment institution or acquiring bank to onboard or continue serving a crypto-related business – is among the most operationally damaging events a digital-asset company can face. It typically arises at the intersection of the operator's licence status, the PSP's own regulatory exposure, and the compliance posture of the underlying acquiring bank. Addressing it requires counsel who understand all three layers simultaneously.
This page sets out the regulated basis for PSP and acquiring relationships in the digital-asset sector, the onboarding process, the structural mistakes that cause bans and terminations, the cross-border angles that multiply risk, and the decision matrix operators should apply before engaging counsel.
Why PSP and Acquiring Agreement Bans Happen – and What the Law Actually Says
A PSP or acquiring ban is almost never a random commercial decision. It is the downstream consequence of a specific gap in the operator's regulatory or compliance profile that the PSP's compliance team has identified – whether or not the PSP articulates that gap clearly in its termination notice.
Acquiring banks and PSPs sit inside regulated payment systems. Under the applicable payment-services regimes – including the Payment Services Directive framework in the EU, the FCA's payment-services rules in the UK, and equivalent regimes in Singapore under the Payment Services Act administered by MAS – a PSP that onboards a customer it cannot adequately monitor for AML/CFT risk assumes that risk itself. That exposure drives termination decisions.
In our practice, the most common structural causes of a ban break down into four categories. First, the operator holds no licence in the jurisdiction from which it serves end users – so the PSP faces an unregulated counterparty. Second, the operator's AML programme is underdocumented: the PSP cannot satisfy its own auditors that its customer's controls are adequate. Third, the operator's transaction volumes or business model fall outside the product category the PSP originally underwrote. Fourth, a change in the PSP's own correspondent banking relationship has made it commercially impossible to continue serving crypto clients, regardless of their individual compliance quality.
Understanding which category applies determines the remedy. A regulatory gap requires a licence or a restructured entity. A documentation failure requires enhanced compliance materials. A scope creep issue requires a re-underwriting conversation. A correspondent banking change may require a new PSP search entirely. Conflating these categories – and many operators do – is the mistake that turns a recoverable situation into a six-month operational crisis.
The process above describes the standard diagnostic path. Your facts – the entity structure, the user base geography, the transaction profile and the banking chain – change the analysis substantially.
For a scoped assessment of your PSP and acquiring position, contact OBOLUS at info@oboluslaw.com. We will map the regulatory gap and the route to a durable solution. Or map your options directly.
What Is the Regulated Basis for PSP Onboarding in the Digital-Asset Sector?
PSP onboarding for a digital-asset business is governed at two levels simultaneously: the regime that licenses the PSP, and the regime that licenses – or should license – the digital-asset operator as its customer.
On the PSP side, the applicable frameworks vary by geography. In the EU, a CASP (crypto-asset service provider) authorised under MiCA – the Markets in Crypto-Assets Regulation supervised by ESMA and the relevant national competent authority – carries a passportable authorisation that EU-licensed PSPs can anchor their due diligence on. In the UAE, an operator holding a VARA licence is a recognisable regulated entity to UAE-domiciled PSPs. In Singapore, a Major Payment Institution or Standard Payment Institution licence under the Payment Services Act gives an operator the MAS-licensed status that local PSPs require. In each case, the PSP is not simply satisfying a commercial preference – it is fulfilling its own compliance obligation to know the regulatory status of its business customers.
On the operator side, the critical threshold is jurisdiction of service, not jurisdiction of incorporation. A BVI-incorporated exchange serving EU retail customers needs a MiCA CASP authorisation – or an EU-based entity that holds one – before a credible EU PSP will maintain the relationship. The same logic applies to the FCA's financial-promotion regime in the UK and the SFC's VASP licensing regime in Hong Kong. Offshore incorporation without a corresponding service-jurisdiction licence is the single most common structural cause of PSP bans we encounter.
The AML dimension compounds this. The FATF's Recommendation 15 on virtual assets, and the Travel Rule (the obligation to transmit originator and beneficiary data with each qualifying transfer), create a compliance standard that PSPs increasingly require their digital-asset customers to demonstrate they meet. An operator that cannot show a documented Travel Rule programme, a functioning transaction-monitoring system and a sanctions-screening process will face friction from any tier-one PSP, regardless of its licence status.
How Does the PSP Onboarding Process Work for a Digital-Asset Business?
Onboarding a PSP or acquiring relationship for a digital-asset institutional client is a structured due-diligence process, not a sales conversation, and operators who approach it as the latter waste months and generate adverse records.
The process typically unfolds in five stages. In the first stage, the operator assembles its regulatory dossier: the licence or registration certificate from the relevant authority (VARA, FSRA, MAS, SFC, the Bank of Lithuania under MiCA transition, or equivalent), the AML/CFT policy documentation, the Travel Rule implementation evidence, and a clear description of the business model and transaction flows. This dossier is the PSP compliance team's primary input. It needs to be complete before any formal application is submitted.
In the second stage, the operator identifies the correct PSP category for its transaction profile. Card-acquiring relationships, SEPA/SWIFT correspondent banking, electronic money institution (EMI) accounts and local payment method integrations each involve different counterparties with different risk appetites. A licensed EMI in the EU may accept a MiCA-CASP operator as a business client where a traditional bank will not. A specialist crypto-friendly PSP may provide card processing at a cost premium that a tier-one bank will not match but that avoids the underwriting uncertainty of a general bank's crypto policy.
In the third stage, the operator submits the formal onboarding application and manages the due-diligence exchange. PSPs at this point typically request enhanced due diligence materials: source of funds for the business, UBO documentation, three to twelve months of transaction data or projections, and a compliance attestation. This stage can take several weeks to several months depending on the PSP's internal queue and the completeness of the dossier.
In the fourth stage, the operator negotiates the agreement terms. This is where counsel adds direct value. A PSP agreement for a digital-asset business carries specific risks: termination-for-convenience clauses that give the PSP broad discretion to exit; reserve and chargeback provisions that can lock capital for extended periods; transaction-category exclusions that may inadvertently cover the operator's core revenue; and audit-right provisions that go materially beyond what a non-crypto merchant would accept. Operators who sign standard PSP agreements without negotiation routinely encounter these provisions in enforcement contexts.
In the fifth stage, the relationship is maintained through ongoing compliance reporting. PSPs expect periodic updates to KYB/KYC files, advance notice of material business-model changes and prompt responses to triggered due-diligence reviews. A relationship that is competently maintained rarely terminates. One that goes dark – where the operator stops responding to PSP compliance queries – almost always does.
How Does Cross-Border Structure Affect PSP and Acquiring Risk?
The cross-border reality of digital-asset businesses is the primary driver of PSP and acquiring complexity, and it is the dimension most commonly underweighted by operators building their payment architecture.
Consider a common structure: a group holding company in the BVI, an operating entity in Lithuania holding a Bank of Lithuania VASP registration (transitioning to MiCA CASP), a custody subsidiary in the ADGM regulated by the FSRA, and an exchange interface serving users in the EU, the UAE and Singapore. The legal question for PSP purposes is not which entity needs a payment relationship – all of them may – but which entity, licensed under which regime, is the contracting counterparty with the PSP, and whether that PSP's own licence authorises it to serve that entity in that capacity.
In our cross-border practice, we regularly advise on structures where a mismatch between the licensing jurisdiction of the operator entity and the licensing jurisdiction of the PSP creates a compliance deadlock. An EU-licensed EMI may not be permitted to maintain accounts for a non-EU-licensed crypto exchange, regardless of the exchange's compliance quality, because its own regulator has restricted the category. Resolving this requires either restructuring the operator entity to create a licensed EU presence, or identifying a PSP whose licence and risk policy permits the relationship.
The banking layer adds further complexity. Most PSPs themselves rely on correspondent banking relationships with tier-one banks, and those banks apply their own crypto-client policies to the PSP's portfolio. A PSP that appears willing to onboard a crypto operator may have a correspondent bank that refuses to process the resulting transactions. The operator discovers this not at onboarding but at first settlement – by which point it has built operational dependency on a relationship with no functional fiat rail beneath it.
Tax and regulatory reporting intersect here as well. An operator collecting merchant payments or exchange settlement flows across multiple jurisdictions generates withholding tax exposure, VAT/GST reporting obligations and regulatory reporting requirements that affect how a PSP agreement should be structured and which entity should be the contracting party. These interactions – between the payment, the licence and the tax layer – are the reason that PSP onboarding for institutional digital-asset clients is a multi-disciplinary exercise, not a banking task alone.
In a recent matter, a digital-asset payments business operating across the EU and the Gulf had its acquiring relationship terminated mid-quarter. The PSP cited AML concerns without specifics. We conducted a structural review, identified a mismatch between the entity holding the processing contract and the entity holding the regulatory licence, and assisted in presenting a restructured onboarding package to a replacement PSP within a matter of weeks. The business restored its fiat rails before the end of the quarter.
What Are the Most Common Structural Mistakes That Cause PSP Bans?
The mistakes that cause PSP and acquiring bans are well-known to experienced counsel and almost universally avoidable with early-stage legal input. They cluster around five recurring patterns.
The first is the wrong contracting entity. The entity that signs the PSP agreement must be the entity that holds the relevant licence and that actually conducts the regulated activity. Operators that route PSP agreements through a holding company, a dormant subsidiary or an offshore SPV – to achieve a commercial purpose like balance-sheet separation – create a regulatory mismatch that PSP compliance teams will eventually identify. The fix is structural, not cosmetic.
The second is an incomplete or outdated regulatory dossier. A licence obtained two years ago that has not been updated with the PSP's annual KYB cycle, combined with an AML policy that predates the operator's current product suite, presents as a compliance gap even where none substantively exists. We advise operators to treat the PSP relationship as a living compliance relationship, with the same discipline they apply to their regulator.
The third is scope creep in the business model. A PSP that underwrote a spot exchange is not necessarily comfortable processing transactions from a lending product or a DeFi aggregator interface that the operator added eighteen months later. Material expansions of business model should be disclosed to the PSP before launch, not after the transaction volume triggers a review.
The fourth is inadequate Travel Rule implementation. PSPs with strong compliance cultures increasingly require evidence that their digital-asset customers meet the FATF Travel Rule standard. An operator that has not implemented a functioning Travel Rule solution – covering originator and beneficiary data transmission for qualifying transfers – will face increasing friction as that expectation hardens into a standard onboarding requirement.
The fifth, and perhaps the most avoidable, is poor legal review of the PSP agreement itself. Reserve clauses that hold settlement funds for extended periods, rolling-termination-for-convenience provisions that give the PSP exit rights on short notice, and audit clauses that require access to the operator's client data on demand are all standard in PSP agreements drafted for non-crypto merchants. For a digital-asset business, these provisions carry amplified risk. Accepting them without negotiation is a structural mistake that surfaces in the worst possible context.
Which PSP and Acquiring Structure Fits Which Operator Profile?
The right PSP and acquiring architecture depends on the operator's regulatory status, transaction profile and geographic footprint. A one-size approach produces the wrong answer for most institutional clients.
An operator holding a MiCA CASP authorisation in an EU member state and primarily serving EU institutional counterparties is best positioned to seek a relationship with an EU-licensed EMI or a specialist crypto-focused payment institution. The CASP authorisation is a recognised regulatory credential. The PSP's own compliance exposure is manageable. The agreement negotiation turns on commercial terms – reserves, settlement cycles, fee schedules and termination mechanics – rather than on whether the relationship is regulatorily permissible at all.
An operator holding a VARA licence in Dubai and serving predominantly MENA and Asian institutional clients faces a different matrix. UAE-domiciled PSPs and EMIs that are themselves regulated or recognised within the UAE financial system are the natural starting point. Where the operator also needs to process EU or UK payments, it requires either a European entity with a corresponding licence or a PSP that holds cross-border permissions and whose compliance team has a documented digital-asset policy. The timeline to establish the second leg of that architecture is typically measured in months.
An operator at an earlier stage – holding a registration rather than a full licence, or in the process of transitioning between frameworks – needs a more conservative approach. Specialist fintech banking platforms and second-tier EMIs may onboard on the basis of a documented compliance programme and a credible regulatory transition plan, where tier-one PSPs will not. The cost differential is real and should be treated as a regulatory transition cost, not a permanent operating expense.
A common assumption is that a single offshore licence is sufficient to maintain PSP relationships globally. It is not. The jurisdiction from which the operator serves its users – not the jurisdiction of incorporation – determines the regulatory credential the PSP is looking for. An operator incorporated in the Cayman Islands and serving European users needs a European licence or a European licensed entity. The CIMA registration may satisfy the Cayman regulator; it does not satisfy a German or French PSP compliance team examining its obligations under MiCA and the applicable AML directive.
If a prior PSP application stalled or a banking relationship was closed, a structural review can surface the underlying cause and the route forward. Write to OBOLUS at info@oboluslaw.com or map your options to discuss the specific situation.
Self-Assessment: Is Your PSP and Acquiring Structure Defensible?
Before approaching a PSP or responding to a compliance review, an institutional operator should be able to answer yes to each of the following questions – or understand precisely why it cannot.
Does the entity signing the PSP agreement hold the licence or registration that the PSP's compliance team will require for the relevant jurisdictions of service? Is the AML/CFT policy current, tailored to the actual business model, and documented to the standard the PSP's auditors will apply? Has a Travel Rule solution been implemented and can it be evidenced? Is the business model described to the PSP consistent with the regulated activities described in the licence? Are the UBO disclosure documents current and complete? Has legal counsel reviewed the PSP agreement's termination, reserve and audit provisions before execution?
If any of these questions produces a qualified answer, that qualification is the starting point for the structural work. In our practice, operators who complete this self-assessment before approaching a PSP convert at a materially higher rate and sustain relationships with materially fewer adverse compliance reviews.
We map the licence stack across operating, custody and payment layers before you commit – so that the onboarding process is a presentation of a defensible structure, not a test of whether one exists.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital-Asset Businesses – the full practice overview covering fiat-rail architecture and account access across jurisdictions
- PSP and Acquiring Agreement: Where the Legal Lines Are Drawn – analytical deep-dive on the contractual and regulatory fault lines in acquiring relationships
- VARA Licence Application: Where the Legal Lines Are Drawn – step-by-step analysis of the VARA authorisation process and its interaction with payment and banking access
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts when the operator's regulatory status, AML programme or transaction profile does not meet the bank's own compliance requirements or the policies of its correspondent banking chain. The most common triggers are an absent or unrecognised licence in the jurisdiction of service, inadequate AML documentation, a business model change that the bank did not underwrite, or a blanket de-risking decision driven by the bank's own regulatory exposure rather than the individual operator's compliance quality.
How can a VASP onboard with an EMI?
A VASP (virtual asset service provider) can onboard with an EMI by presenting a complete regulatory dossier: the relevant licence or registration, a current AML/CFT policy tailored to the actual business model, documented Travel Rule compliance, and clean UBO disclosure. EMIs that are themselves licensed in crypto-permissive jurisdictions – such as EU member states operating under the MiCA regime or Payment Services Act licensees in Singapore – are generally more accessible than traditional banks, but they require the same substantive compliance evidence.
What does client-money safeguarding require?
Client-money safeguarding requires that funds held on behalf of clients are segregated from the firm's own funds, held in designated accounts with qualifying credit institutions, and subject to reconciliation and record-keeping obligations set out in the applicable regime – including the payment-services rules in the EU and UK. For digital-asset businesses that also hold fiat on behalf of clients, the safeguarding obligations of the payment-services licence and the custody obligations of the VASP or CASP licence interact and must be addressed in combination.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – so that PSP and acquiring onboarding is a presentation of a defensible structure, not a test of whether one exists. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in digital-asset regulatory architecture, PSP onboarding strategy and cross-border compliance structuring for institutional operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.