EST · MMXXVI
Home/Services/Banking Payments Emi/PSP and acquiring agreement for Regulated Entities
Banking, Payments & EMI Onboarding

PSP and acquiring agreement for Regulated Entities

Psp and acquiring agreement for Regulated Entities. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

A crypto exchange or payment firm that loses its acquiring relationship does not simply face inconvenience — it faces an operational halt. Card processing stops. Client onboarding freezes. Revenue falls to zero. For regulated digital-asset businesses, the PSP and acquiring agreement (the contractual stack that connects a merchant to card networks, payment processors and settlement accounts) is as fundamental as the operating licence itself. Yet obtaining and retaining that agreement is, in our practice, one of the most consistently underestimated legal challenges in the sector.

The legal question is precise: how does a virtual asset service provider (VASP) — a business licensed to operate in digital assets — secure and protect PSP and acquiring relationships that are subject to card-network rules, banking-sector AML requirements and, increasingly, the licensing obligations imposed by regimes such as MiCA (the EU's Markets in Crypto-Assets Regulation) and VARA (Dubai's Virtual Assets Regulatory Authority)? This page sets out the regulated basis, the process, the common failure points and the cross-border dynamics that define every live engagement we handle.

The regulated basis: why acquiring for VASPs is different

Acquirers and payment service providers treat digital-asset businesses as a distinct, elevated-risk merchant category. That categorization is not arbitrary. Card-network rules — enforced through member banks and acquiring institutions — expressly restrict or condition the onboarding of merchants whose business involves buying, selling or exchanging virtual assets. The relevant gating point is not your own licence status; it is how the acquiring bank and its card-network sponsor classify the business activity.

At the same time, regulatory pressure on the acquiring side has increased. MiCA requires that crypto-asset service providers in the EU hold a CASP authorisation (Crypto-Asset Service Provider authorisation) as a condition of operating. Acquiring banks operating in the EU are now expected to verify that a VASP counterparty holds that authorisation before providing settlement services — or at least before the passporting-based transition periods expire. The practical consequence is that your regulatory status directly affects your acquirer's compliance posture.

Outside the EU, the dynamic is similar. Under VARA in Dubai, activity-specific licences govern every material function; acquiring banks operating in the UAE's mainland will ask for VARA licence documentation as part of the merchant onboarding file. In Singapore, MAS (the Monetary Authority of Singapore) licensing under the Payment Services Act is a near-universal prerequisite for any PSP willing to settle fiat for a crypto business. The asymmetry matters: the acquirer's regulator looks at the merchant's regulatory file. If the file is thin, the relationship either does not happen or it is terminated on the next periodic review.

How PSP and acquiring agreements are structured for digital-asset businesses

A PSP and acquiring agreement for a VASP is typically a layered contract stack, not a single document. Understanding each layer is essential to managing termination risk.

The first layer is the payment processing agreement between the merchant and the PSP. This document governs routing, settlement timing, chargeback liability and the permitted merchant category code (MCC). For VASPs, the MCC assignment is itself a legal decision: an incorrect MCC assignment understates risk to the acquiring bank and can give the bank a contractual termination right with little notice.

The second layer is the acquiring bank's own merchant agreement. This is the document that binds the VASP to the acquiring bank's operating standards, chargeback thresholds and AML/KYC requirements. It typically incorporates by reference the card network's operating regulations — Visa and Mastercard maintain separate frameworks for high-risk merchants — and often includes enhanced due-diligence schedules for crypto businesses. Rolling reserves, extended settlement windows and capped monthly processing volumes are common provisions at this layer.

The third layer is the card-network programme rules. These operate above both contract layers and can override them. A change to the network rules — such as the periodic revisions to how exchanges and custodians are categorized — can effectively reprice or restrict a VASP's access even when the bilateral contracts are in good standing. Monitoring network-rule amendments is ongoing legal work, not a one-time review.

Why do PSP relationships break down for crypto businesses?

The three most common causes of PSP termination for regulated digital-asset businesses are: a change in acquirer risk appetite, a compliance deficiency in the merchant's file, and a card-network rule change that reclassifies the merchant category. In our cross-border practice, a disproportionate share of terminations trace to the second cause — and that is the one most directly in the control of counsel and the client.

A compliance deficiency is rarely a single document. It is typically a combination of factors: an AML policy that has not been updated to reflect Travel-Rule obligations (the Travel Rule being the FATF requirement to pass originator and beneficiary information with a virtual-asset transfer), KYC procedures that do not satisfy the acquiring bank's enhanced due-diligence schedule, and a licence or registration that is either in the wrong jurisdiction or does not cover the full scope of business. Each deficiency is individually manageable. Together, they present the bank's compliance team with a file they cannot approve.

A second recurring cause is reactive rather than proactive contract management. Operators we advise routinely discover that their PSP agreements contain broad discretionary termination rights that can be exercised on limited notice — sometimes as short as two business days. When those clauses are triggered, the remedial options are constrained. The structural solution is to negotiate the termination-notice regime, the cure-period provisions and the restricted-activity definitions before signing, not after a notice arrives.

The AUDIENCE PAIN here is real: operating without the right licence, or with a licence that does not match the acquiring bank's compliance expectations, exposes the business to enforced termination, frozen settlement balances and, in some jurisdictions, direct regulatory action against the business for unlicensed payment activity.

For a scoped assessment of your PSP and acquiring structure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts — the entity, the user base, the banking — change the analysis. Map your options.

EMI onboarding as an alternative path to fiat rails

Where direct acquiring is unavailable or impractical, onboarding with an Electronic Money Institution (EMI) provides an alternative set of fiat rails. An EMI is authorized to issue electronic money and provide payment services; it can give a VASP an IBAN, settlement accounts and, in many cases, access to card-network participation through the EMI's own acquiring relationships. The legal relationship between the VASP and the EMI is itself a services agreement — and it carries its own termination and compliance dynamics.

EMI onboarding for crypto businesses is governed in the EU by the Electronic Money Directive framework and, from a VASP-facing perspective, by the EMI's own risk appetite for digital-asset clients. Under MiCA, EMIs that issue e-money tokens (EMTs) are subject to the regulation's stablecoin provisions. That creates an interesting alignment: EMIs with active EMT programmes have strong operational reasons to develop compliant VASP relationships, because their own regulatory standing depends on demonstrating that their token is used within a regulated payments environment.

The process for EMI onboarding follows a similar documentary architecture to acquiring: a detailed compliance questionnaire, AML/KYC evidence, licence documentation, beneficial ownership disclosure and, increasingly, evidence of Travel-Rule compliance infrastructure. In our practice, the applications that progress fastest are those that arrive with a pre-assembled due-diligence pack — a curated file that answers the EMI's compliance questions before they are asked, rather than in response to a series of information requests that extend the onboarding timeline by weeks.

Cross-border complexity is constant. A VASP licensed in, say, a single EU member state for CASP purposes may hold a MiCA passport for pan-EU service delivery — but the EMI it wants to use may be licensed in a different member state with a different national competent authority's interpretation of the enhanced due-diligence requirements. Aligning the regulatory characterizations across the two institutions is legal coordination work, not simply administrative paperwork.

The cross-border layer: entity, banking, and user base

For a business sitting between a licensing jurisdiction and a user base in another, the legal question turns on where the regulated activity actually occurs — and where the money moves. A VASP incorporated in one jurisdiction, licensed in a second and serving users in a third will encounter three distinct sets of regulatory expectations about PSP and acquiring relationships.

In our cross-border practice, this three-part structure is common. The licensing entity is often placed in a hub chosen for its regulatory efficiency — under MiCA, an EU member state; under the ADGM FSRA (Abu Dhabi Global Market Financial Services Regulatory Authority) regime, for Middle East and Asia-Pacific reach; under the AIFC/AFSA (Astana Financial Services Authority, Kazakhstan) for CIS markets. But the banking and acquiring stack needs to work in each of those dimensions simultaneously.

Card-network rules impose geo-restrictions on acquiring. A VASP's acquiring bank may be willing to process transactions from users in certain markets but will flag or block transaction flows from higher-risk jurisdictions, regardless of the VASP's own licence status. Mapping those restrictions to the actual user geography — before onboarding, not after the first suspicious-activity report — is part of the legal pre-work that determines whether the acquiring relationship is viable for the intended business model.

Currency settlement adds another layer. A multi-currency business that needs settlement in EUR, USD and GBP simultaneously will typically require relationships with more than one banking institution, because few single acquiring banks offer competitive settlement terms across all three. Each relationship requires its own compliance onboarding. Managing the legal file across three concurrent onboarding processes, ensuring consistency in the AML/KYC representations made to each institution, is a coordination task that benefits from a single legal view across the full stack.

What does the PSP and acquiring onboarding process look like?

Onboarding a digital-asset business with a PSP or acquirer proceeds through four substantive stages, each of which requires distinct legal inputs.

The first stage is pre-qualification. The VASP identifies candidate PSPs or acquirers willing to consider digital-asset merchants and conducts a preliminary fit assessment: does the candidate's risk-appetite framework cover the specific VASP activity type (exchange, custody, token issuance), the anticipated transaction volumes and the user geography? This stage is properly legal and commercial work — not merely a relationship exercise — because the candidate's onboarding requirements will drive the structure of the compliance file.

The second stage is due-diligence pack assembly. The compliance file for a digital-asset merchant is typically more extensive than for a standard e-commerce business. It includes corporate structure documentation; the full licence or registration file from the relevant regulator (VARA, MAS, FCA, FSRA or the applicable MiCA NCA); an AML/CFT policy and programme summary; a Travel-Rule implementation statement; a data-protection and privacy framework summary; and, for higher-volume applications, audited financial statements. In our practice, the quality of this pack is the single largest predictor of onboarding speed.

The third stage is contract review and negotiation. The PSP or acquirer presents its standard merchant agreement and schedules. For digital-asset businesses, the critical negotiating points are: the termination-notice period (extending the standard from short notice to a period that allows the business time to find an alternative); the restricted-activity definitions (ensuring that the business model as described in the licence does not inadvertently fall within a broad exclusion); the chargeback liability provisions and associated reserve requirements; and the periodic review triggers that allow the institution to re-underwrite the relationship. Each of these provisions can be negotiated. Few businesses negotiate them without specialist counsel.

The fourth stage is ongoing compliance maintenance. The PSP or acquiring relationship is not a one-time event. Banks and PSPs conduct periodic reviews — typically annually, but triggered-review clauses allow for earlier intervention. Maintaining the relationship requires keeping the compliance file current: updated AML/KYC evidence, renewal of any registration or licence, prompt notification of material changes to the business model or ownership structure. A termination for cause arising from failure to maintain the file is, in our experience, almost always avoidable.

Common mistakes in PSP and acquiring onboarding — and how to avoid them

The most consequential mistake is structural: presenting the acquiring bank with a business model that the merchant's own licence does not clearly cover. If the VASP's licence permits spot exchange but not derivative products, and the acquiring application describes a product roadmap that includes leveraged trading, the compliance reviewer's instinct is to decline. The solution is ensuring that the business-model description in the acquiring application is precisely aligned with the licensed scope — and that any forward-looking elements are clearly flagged as subject to future regulatory approval.

A second common error is misrepresentation by omission. AML questionnaires from acquiring banks ask broad questions about business relationships, counterparty types and source of funds. Operators that answer narrowly — technically accurate but incomplete — create a file that later looks evasive when the bank's ongoing monitoring generates additional questions. The better approach is to answer comprehensively and proactively, with supporting documentation attached, so that the bank's compliance reviewer can approve rather than escalate.

A third mistake is approaching PSP onboarding as a sequential task — finish licensing, then address banking, then address acquiring — when the three tracks are legally interdependent. The licence dictates what activities the acquirer can legally settle; the acquiring relationship constrains the business model the licence covers; the banking structure determines how settlement funds are handled and whether client-money safeguarding obligations are met. We map all three in parallel before a client commits to a licensing jurisdiction, because the optimal licence jurisdiction is partly a function of which acquiring relationships are achievable from that jurisdiction.

A common assumption in the market is that a single offshore licence is sufficient to access PSP and acquiring relationships globally. That assumption is incorrect. Card-network rules and acquiring banks' compliance programmes are informed by FATF country-risk assessments, local money-transmission licensing requirements and card-network-specific merchant-acceptance policies that vary by market. A VASP licensed in a jurisdiction that is not on an acquirer's approved list — regardless of how well-developed the domestic licensing regime is — will be declined or offered terms that are commercially unworkable.

Illustrative matter: recovering fiat rails after a debanking event

In a recent engagement, a licensed European exchange lost its primary acquiring relationship following a routine periodic review that surfaced a gap between its registered AML programme and the Travel-Rule implementation evidence the bank expected. We assembled a remediated compliance file — updated AML/KYC documentation, a Travel-Rule implementation certificate from the exchange's technology provider, and a legal opinion on the scope of its MiCA CASP authorisation — and coordinated simultaneous onboarding applications to three candidate acquirers in parallel. Within several weeks, the exchange had executed an agreement with a new acquirer and had a secondary relationship in documentation. The original relationship was not recovered; the lesson is that parallel-track diversification, pursued before a crisis, is the structural answer to debanking risk.

If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Write to us at info@oboluslaw.com or t.me/oboluslaw to start that conversation. Map your options.

Decision matrix: which approach fits which profile

A direct acquiring relationship is appropriate for a VASP that holds a strong regulatory file — a MiCA CASP authorisation, a VARA licence or an MAS-licensed DPT service — operates in a defined geography, has audited financial statements and is processing at volumes sufficient to justify the acquirer's enhanced onboarding cost. The timeline from application to live processing varies with the completeness of the compliance file. The key risk is termination-clause exposure; negotiating the termination regime is essential at the contract stage.

An EMI-mediated fiat-rails arrangement suits a newer or smaller VASP that cannot meet a direct acquirer's volume or financial-statement requirements but holds a valid licence and a well-documented AML programme. The EMI provides IBAN, settlement and — in many structures — card-network access through its own acquiring membership. The timeline is typically shorter than direct acquiring. The key risk is the EMI's own regulatory standing and the indirect dependence on the EMI's acquiring bank for continued card-network access.

A multi-rail diversification structure — combining a direct acquirer, an EMI relationship and a second acquiring bank — is appropriate for established VASPs with multi-currency, multi-geography operations and significant regulatory investment. This is the resilient structure. Its cost is the overhead of managing three parallel compliance files and three contractual relationships with different periodic-review cycles. The legal benefit is continuity of fiat operations if any single rail fails.

A business that does not yet hold a licence in any flagship jurisdiction should address licensing before pursuing acquiring. The two processes are legally sequenced, even if the timelines overlap.

What does client-money safeguarding require for VASPs with PSP relationships?

Client-money safeguarding is the regulatory obligation — present in most licensed-payment and EMI frameworks — requiring that funds held on behalf of clients be segregated from the firm's own operating capital. For a VASP that holds fiat balances on behalf of clients while executing digital-asset transactions, the safeguarding obligation applies to those fiat balances. The specific form of safeguarding — whether by segregated bank account, insurance or a guarantee from a credit institution — is prescribed by the applicable licensing regime.

Under the EU's electronic-money and payment-services frameworks (which feed into the MiCA environment), safeguarding requirements apply at the EMI or payment-institution level. A VASP that uses an EMI for fiat rails is relying on the EMI's safeguarding compliance; the VASP's own exposure arises if the EMI fails and the safeguarding arrangements prove inadequate. Reviewing the EMI's safeguarding structure is part of the legal due diligence that should accompany any EMI onboarding decision, not an afterthought.

Outside the EU, safeguarding expectations vary. Under the FCA's (Financial Conduct Authority's) regime in the UK, cryptoasset businesses registered under the Money Laundering Regulations are not automatically subject to the FCA's payment-services safeguarding rules — but those that hold fiat balances for clients may trigger a separate regulatory perimeter that requires analysis. In Singapore, MAS's Payment Services Act establishes customer-money safeguarding requirements that apply to licensed DPT service providers. Mapping the safeguarding obligation to the actual business model — rather than relying on a generic description of the licence — is a consistent theme in the compliance work we do for clients at this stage.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily because of perceived AML/CFT risk, card-network compliance obligations and internal risk-appetite limits. The most common immediate triggers are: a periodic review that surfaces a compliance-file deficiency, a chargeback rate above the bank's threshold, or a change in the bank's sector-wide risk policy. A VASP that holds a strong regulatory file — current licence documentation, a documented AML programme and evidence of Travel-Rule compliance — is materially less vulnerable to discretionary termination than one without it.

How can a VASP onboard with an EMI?

A VASP onboards with an EMI by satisfying the EMI's enhanced due-diligence requirements for digital-asset merchants. The process typically requires: a complete corporate structure and beneficial-ownership disclosure; the VASP's current licence or registration documentation from the relevant regulator; an AML/CFT policy summary and evidence of Travel-Rule implementation; and, in many cases, a statement of the VASP's anticipated transaction volumes and user geography. Applications supported by a pre-assembled due-diligence pack progress more quickly than those assembled reactively in response to the EMI's information requests.

What does client-money safeguarding require?

Client-money safeguarding requires a licensed business to hold client fiat balances in a form that is segregated from the firm's own capital and protected in the event of the firm's insolvency. The specific method — segregated bank account, insurance or a credit-institution guarantee — is set by the applicable licensing regime. For VASPs using EMI relationships for fiat rails, the safeguarding obligation at the EMI level is a critical due-diligence point: the VASP's clients are indirectly exposed to the EMI's safeguarding quality.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit — so that the acquiring and EMI relationships you build are grounded in the right regulatory foundation. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums where banking relationships or balances are at risk. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst — specialising in PSP and acquiring compliance, VASP licensing and the cross-border regulatory interactions that determine whether fiat-rail access is achievable for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours