EST · MMXXVI
Home/Services/Banking Payments Emi/PSP and acquiring agreement under Heightened Scrutiny
Banking, Payments & EMI Onboarding

PSP and acquiring agreement under Heightened Scrutiny

Psp and acquiring agreement under Heightened Scrutiny. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOL

Operating a crypto-native business without secured fiat rails (the payment infrastructure connecting a digital-asset platform to the traditional banking system) is one of the fastest routes to a frozen operation. A payment service provider or acquirer willing to work with a virtual-asset business today operates under materially tighter compliance expectations than it did three years ago. Getting the underlying agreement structured correctly – before the PSP's compliance team flags the account – is no longer optional. It is the baseline.

A PSP and acquiring agreement under heightened scrutiny describes the legal and commercial relationship a digital-asset business must establish and maintain with a payment service provider or card acquirer when that counterparty applies elevated due-diligence standards, enhanced monitoring and contractual risk provisions specific to crypto-related activity. The applicable regime spans EMI (electronic money institution) regulatory requirements, Payment Services Act frameworks in Singapore and equivalent legislation across the EU, the UK and the Gulf, plus the anti-money-laundering obligations that flow from FATF Recommendation 15. This page maps the process, the structural decisions and the points where legal counsel materially changes the outcome.

The sections below address the regulated basis for heightened scrutiny, how the agreement is structured, the cross-border considerations that catch most operators, and a decision matrix for different operator profiles.

Why PSP Counterparties Apply Heightened Scrutiny to Crypto Businesses

PSPs and acquirers apply heightened scrutiny to digital-asset businesses because their own regulators require it. That is the short answer. A payment institution processing transactions for a VASP (virtual asset service provider) inherits AML and sanctions exposure from that VASP's customer base. The acquiring bank or EMI becomes, in effect, a regulated chokepoint. If the VASP's compliance is weak, the PSP faces examination findings, correspondent-bank pressure and, in the most serious cases, enforcement.

Under MiCA, the EU's Markets in Crypto-Assets Regulation, and under the FCA's registration regime in the United Kingdom, VASPs are expected to demonstrate to any financial counterparty that they hold the appropriate authorisation or registration, that they have implemented the Travel Rule (the obligation to pass originator and beneficiary data with a transfer), and that their AML programme meets a standard the PSP's own regulator would find acceptable. PSPs that skip this due diligence attract supervisory criticism. They do not skip it.

In our practice, the PSP or acquirer's legal and compliance team effectively conducts a shadow licensing review of every crypto client it onboards. The strength of the VASP's regulatory documentation – the licence, the AML policy, the compliance officer's CV, the ownership structure – determines whether the relationship proceeds and on what commercial terms.

The process above describes the standard path. Your facts – the entity structure, the user base geography, the banking counterparty's home regulator – change the analysis significantly. To get a scoped assessment of where your structure stands, contact OBOLUS at info@oboluslaw.com.

What Is the Regulated Basis for the Agreement?

The PSP acquiring agreement for a crypto business rests on two regulatory foundations simultaneously: the payment regulation that governs the PSP, and the virtual-asset regulation that governs the client. Both sides of that equation must be clean before a compliant agreement is executable.

On the PSP side, the operative regime is typically the EU Payment Services Directive framework (for an EU-licensed EMI), the UK's Payment Services Regulations (for a FCA-authorised institution), MAS's Payment Services Act in Singapore, or an equivalent framework in whichever jurisdiction the EMI is authorised. Each of those regimes requires the EMI to conduct business-relationship risk assessments of its clients. A crypto business triggers the highest risk tier under most of those assessments by default, regardless of the quality of its compliance programme.

On the VASP side, MiCA's CASP authorisation (crypto-asset service provider licence) is the most consequential development in the EU. A MiCA-authorised CASP presents a materially cleaner profile to an EU EMI than an unregistered or offshore-only entity, because the EMI can point its own regulator to the CASP's authorisation as independent evidence of compliance standards. The same logic applies under VARA in Dubai, under ADGM/FSRA in Abu Dhabi, and under the SFC's VASP licensing regime in Hong Kong. Recognised authorisation shortens the EMI's due-diligence burden, which translates directly into faster onboarding and better commercial terms.

Where the VASP operates across borders – licensed in one jurisdiction, banking in a second, serving users in a third – the agreement must address which regulatory standard governs, what notifications are required on a change of regulatory status, and how AML obligations are allocated between the parties. These are not boilerplate provisions. They are negotiating points.

How Is a PSP Acquiring Agreement Structured for a Crypto Business?

A well-structured PSP acquiring agreement for a digital-asset business contains provisions that a standard commercial payment agreement does not. Understanding those provisions is the first step to negotiating them effectively.

The core commercial terms – interchange rates, settlement cycles, reserve requirements, chargeback thresholds – are present in any acquiring agreement. For a crypto client, those terms typically include a higher rolling reserve, a longer settlement delay and a lower chargeback-ratio tolerance before the PSP has the contractual right to suspend the account. Each of those figures is negotiable, and the VASP's compliance documentation is the most effective negotiating lever.

Beyond the commercial terms, heightened-scrutiny agreements typically include the following structural provisions:

  • Enhanced due diligence clauses requiring the VASP to supply AML-programme documentation, licence copies and material-change notices on a defined schedule.
  • Regulatory-change triggers giving the PSP the right to suspend or terminate on a change in the VASP's licence status – without necessarily requiring a breach of the payment agreement itself.
  • Transaction-monitoring cooperation obligations requiring the VASP to respond to transaction queries within a defined period and to cooperate with law-enforcement production requests.
  • Sanctions and OFAC/OFSI screening representations confirming the VASP's screening programme covers its customer base on a continuous basis.
  • Stablecoin and settlement-asset provisions where the agreement contemplates on-chain settlement, confirming which assets are accepted and the conditions for a shift to fiat-only settlement.

In a recent matter, a payments company approaching a mid-tier European EMI for card-acquiring services found that the EMI's draft agreement contained a unilateral right to reclassify the account as high-risk with 48 hours' notice. We negotiated that provision to require a material compliance event before reclassification, and to require 30 days' notice before termination absent a regulatory direction. The client preserved operational continuity. The negotiation took two drafting rounds.

What Are the Cross-Border Complications?

For a digital-asset business, the cross-border reality of payment relationships is where most structuring errors concentrate. A VASP licensed in one jurisdiction often discovers that its licence does not satisfy the due-diligence expectations of a PSP regulated in a second jurisdiction – particularly when the PSP's home regulator has issued crypto-specific guidance that the VASP's home regime has not addressed.

The mismatch plays out in three common patterns:

  • A MiCA-licensed CASP banking with a UK FCA-regulated EMI. The UK institution applies its own AML rules and FCA crypto expectations, which are distinct from MiCA. Passporting does not extend to commercial banking relationships. The CASP must present UK-specific compliance evidence.
  • A BVI FSC-registered VASP seeking acquiring services from a Singapore MAS-licensed payment institution. MAS's DPT (digital payment token) service rules require the PSP to satisfy itself about the counterparty's AML standard. A BVI registration will rarely satisfy that standard without supplementary documentation.
  • A VARA-licensed exchange in Dubai seeking card-acquiring services through a European EMI. VARA's rulebooks are recognised in the UAE but not yet formally recognised in the EU. The EMI must conduct its own assessment, which adds timeline and conditions.

Operators we advise routinely discover these mismatches after they have signed a term sheet with a PSP, not before. By that point, the leverage to negotiate the due-diligence conditions has largely dissipated. The correction is to map the PSP's regulatory expectations against the VASP's licence stack at the term-sheet stage, before commercial terms are agreed.

A further cross-border complication is the client-money safeguarding obligation (the regulatory requirement that an EMI or payment institution ring-fences customer funds in a segregated account). Where a VASP is both holding customer fiat balances and facilitating on-chain settlement, the question of whose safeguarding obligation covers those balances – the VASP's or the EMI's – must be resolved in the agreement before either party's regulator asks the question.

What Are the Most Common Mistakes at This Stage?

The most damaging mistake is treating the PSP relationship as a commercial negotiation rather than a regulatory one. Several patterns appear repeatedly in the matters we work on.

First: presenting an incomplete licence stack. A VASP that holds a VASP registration but has not implemented a compliant Travel Rule solution, or whose beneficial ownership documentation does not match its AML policy, will fail the PSP's compliance review even if the headline licence is in order. The PSP is reviewing the compliance programme, not merely the licence certificate.

Second: accepting the PSP's first-draft agreement without negotiating the risk provisions. The rolling reserve, the chargeback threshold and the termination triggers in the first draft are set for the PSP's protection. They are not fixed. A VASP with a clean compliance record and strong documentation has real negotiating leverage, but only if that leverage is used before signature.

Third: failing to address regulatory-change scenarios contractually. The crypto regulatory environment is shifting materially. A VASP that holds an EMI onboarding today under a legacy VASP registration may find that the same registration is insufficient under MiCA's CASP authorisation requirement. If the agreement does not contain a transition-period provision, the PSP can terminate on the registration change without any obligation to allow time for the CASP application to complete.

A common assumption in the market is that once a PSP relationship is established, it is stable. In our experience, EMIs and acquirers conduct periodic compliance reviews of their crypto clients, typically annually. A relationship that passes onboarding can be suspended or terminated at review if the VASP's compliance documentation has not kept pace with regulatory expectations.

Which Structure Fits Which Operator Profile?

Operator profiles differ materially, and the right PSP structure depends on where the business sits in the regulatory stack.

Profile A – A MiCA-authorised CASP with EU user base: The strongest position. The CASP licence signals to any EU EMI that the VASP's compliance standard has been independently assessed. The negotiating priority is the commercial terms – reserve level, settlement cycle – rather than the compliance conditions. Timeline to onboarding, once documentation is in order, is typically a matter of weeks rather than months for a prepared applicant.

Profile B – A VARA-licensed exchange seeking global card acquiring: VARA authorisation is credible and recognised in the Gulf. For European or Asian PSPs, it requires supplementary due diligence. The structure should include a written compliance summary mapped to the PSP's home-regulator expectations, supported by a legal opinion from allied counsel in the relevant jurisdiction confirming the equivalence basis. That opinion can substitute for an additional local registration in some cases.

Profile C – An early-stage operator holding only a BVI or Cayman registration: The most exposed profile. Most tier-one and tier-two EMIs will not onboard this structure without a concurrent application for a substantive licence in a recognised hub. The practical advice is to pursue the licence and the PSP relationship in parallel, presenting the PSP with the in-progress application and a projected completion date. Some EMIs will onboard on a restricted basis pending authorisation. Most will not.

Profile D – A licensed exchange with a compliance gap (no Travel Rule solution, no comprehensive screening programme): Even a strong licence does not solve a compliance gap. The PSP's compliance team will identify the gap at due diligence. The priority is to close the gap before approaching the PSP, not to approach and remediate under time pressure once the relationship is already at risk.

If a prior PSP application stalled or an EMI account was closed, a second review can identify the structural reason and the route back. Contact OBOLUS at info@oboluslaw.com or via t.me/oboluslaw to discuss your situation.

Self-Assessment: Is Your Business Ready for Heightened-Scrutiny Onboarding?

Before approaching a PSP or acquirer, a digital-asset business should be able to answer yes to each of the following questions. Where the answer is no or uncertain, that item represents a gap the PSP's compliance team will find.

  • Does the business hold a current VASP licence or CASP authorisation in a jurisdiction the target PSP's regulator recognises?
  • Is the AML programme documented, up to date, and aligned with the FATF Recommendation 15 standard?
  • Has a Travel Rule compliance solution been implemented, and can the business demonstrate live data flows to the PSP?
  • Is the beneficial ownership structure clean, documented and consistent with the licence application?
  • Are customer funds – to the extent held in fiat – identifiably safeguarded in accordance with the applicable payment regulation?
  • Is there a named compliance officer with a documented profile suitable for the PSP's review?
  • Has the draft PSP agreement been reviewed by counsel familiar with both the payment regulation and the virtual-asset regime applicable to the business?

Operators who can answer yes to all seven items are in a materially stronger position than those who cannot. We map the licence, compliance and documentation stack as a single pre-onboarding mandate, so that the approach to the PSP is structured rather than reactive.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily because the account's transaction profile creates AML and regulatory risk they are not equipped or willing to manage. In most cases, the immediate trigger is a compliance review that finds the VASP's AML programme, licence documentation or beneficial ownership disclosure to be insufficient. A secondary trigger is correspondence-bank pressure: the bank's own upstream correspondent may restrict crypto exposure, leaving the account as collateral damage regardless of the individual client's compliance quality. Structural remedies – a cleaner licence, a stronger programme, a different banking relationship – address the root cause rather than the symptom.

How can a VASP onboard with an EMI?

A VASP seeking EMI onboarding should approach the process as a regulatory presentation, not merely a commercial application. The practical sequence is: confirm the EMI's home-regulator expectations for crypto clients; prepare a compliance pack covering the VASP licence, AML policy, Travel Rule solution, beneficial ownership chart and compliance officer profile; engage the EMI at the term-sheet stage so that due-diligence conditions and commercial terms are negotiated together. VASPs holding recognised authorisation – a MiCA CASP, a VARA licence or a MAS DPT licence – typically achieve faster onboarding and better terms than those relying on offshore-only registrations.

What does client-money safeguarding require?

Client-money safeguarding requires a payment institution or EMI to hold customer funds in a ring-fenced account segregated from the institution's own funds. The specific requirements – the account structure, the eligible institution, the reconciliation frequency and the notification obligations – are set by the applicable payment regulation in the EMI's home jurisdiction. For a digital-asset business holding fiat on behalf of customers pending on-chain settlement, the question of whether the safeguarding obligation rests with the EMI or with the VASP must be resolved in the account or services agreement. Regulators in the major payment hubs treat an ambiguous allocation of that obligation as a compliance deficiency in both parties.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before clients commit to a structure – and we treat licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP authorisation, EMI onboarding and cross-border AML programme review for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours