A payment firm can receive a merchant’s settlement proceeds on Monday and be expected to pay suppliers, affiliates or customer withdrawals by Tuesday. If the money is held incorrectly, however, it can become a regulatory breach, a banking problem and a serious balance-sheet risk at the same time. So, can payment firms hold client funds? Yes, but only within a tightly defined regulatory and contractual framework.
For payment institutions, electronic money institutions and payment businesses serving high-risk sectors, the real question is not whether funds can touch the firm’s accounts. It is what the funds represent, how long they are held, where they are segregated, and whether the firm has the licence and controls to handle them.
Can payment firms hold client funds under their licence?
In the UK and EU, regulated payment firms may hold funds received for the execution of payment transactions. Electronic money institutions may also receive funds in exchange for issuing electronic money. Neither permission is the same as being allowed to accept deposits or use customer balances as working capital.
A payment institution generally holds money only for the period necessary to execute a payment transaction. An electronic money institution can hold customer value in the form of e-money, subject to redemption rights and safeguarding obligations. The exact permissions depend on the authorisation held, the jurisdiction, and the activities described in the firm’s regulatory programme.
This distinction matters commercially. A firm may be able to collect card-acquiring proceeds, hold a rolling reserve, pay out merchants, and process refunds. It cannot simply retain those proceeds indefinitely, lend against them, finance payroll from them, or treat them as unrestricted cash. Doing so can move the business towards deposit-taking, unauthorised lending, misuse of safeguarded funds, or a breach of prudential requirements.
For Cyprus-based and EU-facing operators, the framework is shaped by the Payment Services Directive and Electronic Money Directive, as implemented locally. In the UK, the Payment Services Regulations and Electronic Money Regulations sit alongside FCA expectations. The detail differs by market, but the central principle is consistent: client money must remain protected from the firm’s own creditors and operational risks.
Safeguarding is the centre of the answer
Safeguarding is not a marketing term or a bank-account label. It is the legal and operational process used to protect relevant customer funds when a payment firm fails. In practice, it requires a clear separation between client funds and the firm’s own money.
A firm commonly safeguards by placing client funds in a segregated account with an authorised credit institution, central bank or qualifying custodian. Depending on the regime, it may instead use an insurance policy or comparable guarantee. For most operating payment businesses, dedicated safeguarding accounts are the practical route.
The account structure alone is not enough. The firm must identify which incoming funds are relevant funds, calculate the amount that must be safeguarded, reconcile it against bank balances, resolve discrepancies quickly, and document its methodology. It also needs clear records showing the underlying customer or merchant entitlement at any moment.
A simple example illustrates the pressure point. A merchant receives £500,000 in card settlements, while the payment firm charges £15,000 in fees. Until settlement and deductions are properly allocated, the majority is not the firm’s revenue. The firm may have a contractual right to fees, chargebacks, reserves or set-off in defined circumstances, but these rights must be drafted carefully and applied through a transparent ledger process. Treating the full £500,000 as available operating cash would be a serious mistake.
Funds in transit still require a policy
Many businesses assume that money is outside safeguarding while it is moving through correspondent banks, card schemes or an acquiring partner. That assumption is dangerous. Firms need a documented point at which money is considered received, a clear treatment of funds in transit, and a process for timing differences between internal ledgers and external accounts.
This is particularly relevant for multi-currency, cross-border and high-volume payment flows. Cut-off times, weekend settlement, foreign-exchange conversion, chargeback exposure and scheme reserves can all create reconciliation gaps. A regulator will expect the firm to understand those gaps rather than explain them after a complaint, audit or insolvency event.
What payment firms cannot do with client money
The commercial temptation is obvious. Client balances can be substantial, especially for gaming, crypto-adjacent and marketplace payment flows. Yet safeguarded money is not a cheap source of liquidity.
A payment firm should not use client funds to fund its own expenses, meet capital requirements, make loans, invest for proprietary return, or support another group company. It should not obscure client money within a general operating account simply because the firm maintains accurate spreadsheets. Nor should it accept funds for services it is not authorised to provide.
The same principle applies to reserves. A rolling reserve can be commercially legitimate where it addresses chargeback, fraud or refund risk, especially in card-not-present and high-risk merchant sectors. But the reserve must have a contractual basis, a rational methodology, clear release conditions and proper safeguarding treatment. An open-ended reserve with no meaningful explanation can become a client-money dispute as well as a reputational issue.
Firms must also avoid presenting safeguarded funds as if they were protected by a traditional deposit guarantee scheme. Safeguarding aims to improve the return of customer money if the firm fails. It is not the same legal protection as a bank deposit, and customer communications should make that distinction accurately.
Licensing determines the permitted business model
Before launching a payment product, founders should map the intended money flow from payer to beneficiary. This exercise often exposes a licensing issue early enough to solve it properly.
If the business only introduces merchants to licensed acquirers, it may not need to receive client funds at all. If it accepts money into named accounts and instructs onward payments, it may be providing payment services. If it stores value for later use, issues wallets or enables transfers between users, e-money regulation is likely to be relevant. If crypto-assets enter the flow, MiCA and local CASP requirements may create a separate but connected regulatory analysis.
There is no safe shortcut in calling a regulated activity ‘technology’, ‘agency’ or ‘software’ when the company controls the payment instruction, contractual relationship or customer funds. Regulators and banks assess substance over labels. So do sophisticated merchants and investors conducting due diligence.
For groups operating across several jurisdictions, the issue extends beyond the licence itself. The operating entity, contracting entity, safeguarding account holder, technology provider, treasury company and intellectual-property owner should have defined roles. A poorly designed structure can create tax leakage, regulatory ambiguity and difficulty obtaining banking support. A well-designed structure creates cleaner governance, easier reporting and a credible foundation for international growth.
High-risk merchants need stronger operational controls
Online gaming, sports betting, adult, affiliate, crypto and cross-border digital businesses bring heightened scrutiny because their payment patterns can involve rapid turnover, fraud attempts, chargebacks, sanctions exposure and source-of-funds concerns. Holding client funds in these sectors is possible, but a generic compliance manual will not satisfy banking partners or regulators.
The payment firm needs merchant onboarding standards that match its risk appetite, ongoing transaction monitoring, sanctions screening, suspicious-activity escalation, fraud controls and clear rules for delayed settlement. Its safeguarding process should be tested against difficult scenarios: a bank account freeze, a scheme holdback, a merchant insolvency, a sudden increase in refunds, or the failure of a key payment partner.
Capital and liquidity planning matter just as much. Safeguarding protects relevant customer money, but it does not pay the firm’s rent, legal costs, chargeback losses or remediation expenses. A business can be technically compliant on safeguarding and still fail because it lacks sufficient own funds and available liquidity. Founders should model both sides of the balance sheet from the start.
Build the payment flow before accepting the first transaction
The strongest payment businesses treat client-fund handling as an operating design question, not a compliance task to complete after launch. The legal agreements, ledger architecture, banking arrangements, safeguarding policy, reconciliation process and incident plan should all describe the same flow of money.
This is where specialist structuring adds practical value. The right licence and jurisdiction can support market access, but the operating model must also withstand merchant due diligence, bank reviews, audits and future acquisition scrutiny. Ivyascent helps founders align licensing, corporate structure, payment-rail strategy and legal documentation so growth does not depend on a fragile interpretation of the rules.
Before accepting the first pound, euro or dollar, make sure every party can answer one straightforward question with confidence: whose money is this, where is it protected, and what happens if the firm cannot complete the payment?