Agent, distributor, passported entity: what each status allows
A distributed payment program is an arrangement in which a licensed institution provides the payment services while another entity owns the relationship with the end customer. The two go to market under the second entity's brand. EU law does not define banking-as-a-service: the term appears in no directive and no public register. The law recognizes three positions: the licensed institution, the person acting on its behalf, and the entity to which an operational function is outsourced. Responsibilities follow from these three positions, never from the labels in the commercial contract. Words like “partner” or “program” have no legal effect in themselves.
An agent provides payment services on behalf of a payment institution or an e-money institution. It holds no license of its own. Instead, it is registered with the competent authority, which is a separate administrative step. A license entitles its holder to provide payment services in its own name, while registration only authorizes the agent to act on behalf of its principal. The agent's scope is capped by the services the principal is itself licensed to provide, and by those the mandate expressly covers. An agent therefore cannot provide any service its principal is not licensed for. The mandate can narrow the scope of the license, never widen it.
An e-money distributor is a natural or legal person that distributes and redeems e-money on behalf of the institution that issued it. Its position resembles an agent's, but its regime differs: it is not subject to any registration equivalent to the agent's. Article 3(4) of Directive 2009/110/EC requires member states to allow this delegation. Article 3(5), however, prohibits issuing e-money through agents. Distribution, loading, and redemption can therefore be handed to a third party, but issuance remains the licensed institution's own act. The holder's claim is always against the issuing institution, whatever brand the app displays.
| License type | Who holds the license | What it allows | What it never allows |
|---|---|---|---|
| Payment institution | The institution itself, granted by its home state authority | The PSD2 Annex I services covered by its license, across the EEA once passported | Taking deposits in the banking sense; issuing e-money without a separate license |
| E-money institution | The institution itself | Issuing e-money, plus the payment services covered by its license | Delegating issuance itself to a third party |
| Agent | The principal institution, never the agent | Providing, on the institution's behalf, the payment services covered by the mandate and listed in the register | Issuing e-money; providing a service the principal is not licensed to provide |
| E-money distributor | The issuing institution | Distributing and redeeming e-money issued by the institution | Issuing e-money, and thus creating the claim on the institution |
Passporting extends a license granted in one member state to the entire European Economic Area. It works through two freedoms that trigger different obligations. The freedom to provide services lets an institution serve a market from its home state, with no local presence. The freedom of establishment covers branches, agents, and, for e-money institutions only, distributors. The second regime gives the host country's supervisor oversight rights that the first does not.
Regulators long drew the line between the two freedoms differently. The European Banking Authority's opinion of April 24, 2019 set a common reading. It covers institutions that use agents or distributors located in another member state, and followed the discovery of significant differences between national authorities. The opinion sets three criteria. The first is whether the task is occasional or regular and ongoing. The second is the overall length of the contractual relationship. The third is whether customers can use the service in their own member state. Under these criteria, an agent permanently based in a market and serving its customers falls under the freedom of establishment, while a one-off, time-limited activity falls under the freedom to provide services.
The framework is being revised. On November 27, 2025, the European Parliament and the Council reached a provisional political agreement on the third Payment Services Directive and its accompanying regulation. The draft folds e-money institutions into payment institutions as a subcategory, repeals Directive 2009/110/EC, and brings the distributor regime closer to the agent regime. It requires an orderly wind-down plan covering the continuity of critical activities performed by outsourcing providers, agents, and distributors. The texts had not been published in the Official Journal as of September 2026; the final compromise texts of April 23, 2026, set a transposition period of 21 months after entry into force.
Registration, the public register, and agent passporting
Agent registration is the entry of the agent, by the competent authority and in a public register, as a party authorized to provide payment services in an institution's name. Article 19 of PSD2 governs it. An institution that intends to provide payment services through an agent submits an application to the competent authority of its home state. The authority verifies the information and refuses registration if it does not consider it accurate. The application covers the agent's identity, its internal anti-money laundering controls, the people who run it, and the exact scope of the mandate.
- The agent's name and address, the only item everyone provides without being asked.
- A description of the internal control mechanisms the agent uses to meet anti-money laundering and counter-terrorist financing obligations, to be updated without delay after any material change.
- The identity of the agent's directors and managers responsible for providing payment services, with evidence that they are fit and proper when the agent is not itself a payment service provider.
- The institution's payment services the agent is mandated for, listed service by service rather than by a blanket reference to the license.
- The agent's unique identification code, where there is one.
The authority has two months from receiving the information to tell the institution whether the agent has been entered in the register. Article 19(2) attaches the legal effect to that entry. The agent may start providing payment services as soon as it is entered in the register, and has no right to do so before then. The authorization comes from the register, so the effective date of the commercial contract makes no difference. A program launched before registration has payment services provided by an unauthorized person, and the principal institution is liable for it.
Two registers coexist, with different evidentiary weight. Article 14 of PSD2 requires each member state to keep a national public register, available online and updated without delay, that identifies the services covered by each license or registration. Article 15 tasks the European Banking Authority with a central electronic register that reproduces the national registers. The split of responsibilities between the two levels is explicit. The EBA answers only for faithfully reproducing what it receives, while the national authorities, which feed and update the data, are responsible for its accuracy.
Engaging an agent in another member state triggers the Article 28 passporting procedure, which takes longer and involves more scrutiny. The home authority forwards the application to the host authority within one month of receiving it. The host authority then has one month to assess it and send its comments, particularly if it has reasonable grounds to suspect a money laundering or terrorist financing risk linked to the plan. The home authority decides within three months of receiving a complete application, enters the agent in the register, and then notifies its decision to the host authority and the institution.
A central contact point is the person or entity an institution appoints in a host state to represent its network before the local authority. The obligation arises once the agent network reaches a significant size in that country. Two central contact point regimes coexist, with different legal bases and different thresholds. The first is an anti-money laundering regime, based on Article 45(9) of Directive (EU) 2015/849 and detailed in Delegated Regulation (EU) 2018/1108 of May 7, 2018. The second is prudential, based on Article 29 of PSD2 and detailed in Delegated Regulation (EU) 2020/1423 of March 14, 2019.
| Regime | Legal basis | Triggering thresholds | Expected functions |
|---|---|---|---|
| Anti-money laundering | Article 45(9) of Directive (EU) 2015/849; Delegated Regulation (EU) 2018/1108 | 10 or more establishments in the host state; or cumulative e-money distributed and redeemed, or cumulative value of transactions executed, above €3 million in a financial year or expected to reach that level; or information not available on request | Ensure the establishments comply with AML/CFT rules, report failures to head office, get them fixed, represent the institution before the authority, and facilitate on-site inspections |
| Prudential and supervisory | Article 29 of Directive (EU) 2015/2366; Delegated Regulation (EU) 2020/1423 | 10 or more agents under the freedom of establishment; or total transaction value above €3 million with at least two agents; or more than 100,000 transactions in the last financial year with at least two agents | Act as the single reporting point for the host authority, handle communications with it, and facilitate its inspections |
National transpositions add formalities that neither delegated regulation contains. Italy offers the best-documented example. Agents providing payment services in Italy on behalf of an institution from another member state must report their activity to the OAM (Organismo Agenti e Mediatori, Italy's register of financial agents and credit brokers). The report covers the start of activity, updated information, changes, and termination. It is sent by certified email, under Article 128-quater, paragraph 7, of the Testo Unico Bancario. These agents are not entered in the special section of the list reserved for agents of Italian institutions. That does not exempt them from reporting, which rests on a separate legal basis.
Who does KYC, who monitors, and who stays liable
Article 20 of PSD2 establishes the principal institution's full liability. Member states must require the payment institution to remain fully liable for all acts of its employees and of any agent, branch, or entity to which activities are outsourced. That liability covers the entire scope, however the parties divide tasks between them. No agreement can transfer it. A contract can allocate the workload, financial compensation, and burden of proof among its signatories. But before the supervisor, only the institution answers for failings found at its agent.
The duty to monitor agents starts with the license application, before any agent is registered. Article 5(1)(l) of PSD2 requires the applicant to describe its organizational structure, including its planned use of agents and branches. It must also describe the off-site and on-site checks it commits to performing on them at least once a year. That frequency is written into the EU text itself. An institution with no enforceable annual control plan departs from the organization it described to obtain its license. The gap is therefore more than an operational weakness: it concerns the very description on which the license was granted.
Know your customer (KYC) covers collecting the user's identity data, verifying it, and classifying the customer by risk level. The split between the institution and its partner almost always follows the same pattern. The partner runs the interface, collects ID documents, records the verification video, and absorbs the drop-off rate. The institution is the obliged entity: it decides whether to onboard, sets the risk classification, rules on alerts, and signs the suspicious activity report. The setup holds as long as the institution can access the documents the partner collected. It breaks down as soon as the institution sees only an aggregated status, because its decision then becomes a formality and its monitoring rests on the partner's word.
- Ongoing access to the document itself, not just to the result of the check. The raw customer file, images, timestamps, and decision log must be viewable from the institution's systems.
- On-site audit rights, exercisable without long notice and extended to the partner's subcontractors through flow-down clauses.
- The right to rerun screening on the partner's customer base with the institution's own tools and lists, to test something other than the partner's compliance with its own rules.
- Direct access for the supervisor and, where one exists, the resolution authority, written into the contract and enforceable against subcontractors.
- Full return of data on exit, in a usable format, within a set deadline, with retention guaranteed for the statutory retention period.
- No subcontracting of data collection without prior written consent; otherwise the chain extends beyond the reach of the original contract.
German supervision offers a documented precedent of measures against an institution whose oversight of its partner network was found deficient. On December 16, 2022, BaFin ordered Solaris SE to ensure proper business organization in risk management and anti-money laundering, a measure that became final on January 25, 2023. The order barred the institution from entering into new cooperation partnerships without the supervisor's prior approval, and a special representative was appointed under Section 45c of the Kreditwesengesetz (German Banking Act). A second order, published on July 12, 2024, targeted failings in anti-money laundering, regulatory reporting, outsourcing management, and IT systems. The special representative's mandate was extended.
Agency or outsourcing: two regimes, two sets of obligations
Outsourcing means using a third party to perform an operational function the institution would otherwise perform itself. An agency mandate puts the third party in a position to provide the payment service to the user, in the institution's name and on its behalf, and the user must be told so. Article 19 of PSD2 deals with agents, branches, and outsourcing providers together. Yet the obligations attached to each differ on almost every point. The dividing line between the two regimes is the relationship with the payment service user. An outsourcing provider performs a function for the institution without providing the service itself and without any payment relationship with the user.
| Issue | Agent or distributor | Outsourcing provider |
|---|---|---|
| Relationship with the user | Provides the service in the institution's name and tells the user it is acting on the institution's behalf | No payment relationship with the user |
| Filing with the supervisor | Prior registration of the agent, which is a precondition: activity starts upon registration. Directive 2009/110/EC imposes no equivalent registration for distributors | Notice to the home authority, with no entry in the public register |
| Public visibility | The agent appears in the national register and the EBA central register, which has no “distributor” category | Does not appear in any public register |
| Cross-border activity | Triggers the Article 28 passporting procedure and, above the thresholds, a central contact point | Does not in itself create an establishment in the provider's country |
| Classification to watch | Exact scope of the mandated services, service by service | Whether the outsourced operational function is important |
| Liability | The institution remains fully liable (Article 20) | The institution remains fully liable (Article 20) |
PSD2 Article 19(6) defines an important operational function by the consequences of its failure rather than by its nature. A function is important if a defect or failure in its performance would seriously impair one of three things: the institution's ability to keep meeting its license conditions, its financial performance, or the soundness and continuity of its payment services. The same paragraph sets four cumulative conditions. Senior management cannot delegate its responsibility. The relationship with users and the obligations toward them remain unchanged. The license conditions are not undermined. And none of those conditions is removed or modified.
The European Banking Authority's guidelines EBA/GL/2019/02 were published on February 25, 2019, and have applied since September 30, 2019. ⚠️ They are due to be replaced: on September 18, 2026, the European Banking Authority published its final guidelines on managing third-party risk for non-ICT services. These align the framework with DORA, focus the obligations on critical or important functions, and provide for a two-year transition period. The application date has not yet been set, as the text awaits translation into the EU's official languages. The current guidelines extend to payment and e-money institutions an outsourcing framework that the earlier guidelines of CEBS, the EBA's predecessor, reserved for credit institutions and investment firms. They require a risk assessment and due diligence before contracting, then a written contract with minimum content. They also require a register of all outsourcing arrangements that flags those covering critical or important functions. On top of this come audit and access rights for both the institution and the authorities, rules on chain outsourcing, and a documented exit strategy. The register is the first document a supervisor asks for in an inspection, because it lists all outsourcing arrangements in one place and flags those covering critical or important functions.
Regulation (EU) 2022/2554, known as DORA, which has applied to payment and e-money institutions since January 17, 2025, has taken over the IT side. Arrangements with third-party ICT service providers now fall under its register of information and its own concept of critical or important functions. It has its own contractual requirements and resilience testing. The outsourcing guidelines still apply to arrangements that do not involve IT services. In 2025, the European Banking Authority consulted on extending this framework to all third-party arrangements outside DORA, a sign that the boundary is not yet settled.
When a program shuts down, and what the end customer is left with
Supervisors act on a distributed program in stages, and the first ones go unnoticed by end customers. The first stage is an order to remediate, with deadlines, sometimes periodic penalty payments, and a monitor appointed by the authority to check compliance. The second is a freeze on onboarding, which may target new customers, new agents and distributors, or new partnerships. The third is license withdrawal, whose grounds Article 13 of PSD2 lists, from not using the license for 12 months to posing a threat to the stability of the payment system.
The Lithuanian timeline shows how long it takes from the first public measure to the institution's disappearance. The onboarding freeze came in February 2023 and the license withdrawal on June 22, 2023, followed by bankruptcy proceedings. Four months separate the freeze from the withdrawal. The freeze was public, so the hosted programs had a warning before the final decision. Yet even an exit plan launched at that point runs behind the technical timeline, because reissuing cards takes months, not weeks.
Moving a program to another institution means completely reissuing its instruments and account details. IBANs assigned under the institution's BIC do not follow the program, and neither do virtual IBANs allocated from its ranges. BIN ranges depend on the issuer's scheme license, so they stay with the issuer. The KYC file is portable in theory, but whether the new institution accepts it depends on the quality of the audit trail, not on a contract clause. A program that changes institutions changes its bank details, card numbers, and customer contract. The only things that survive the migration without being rebuilt are the commercial relationship, and the KYC file if its audit trail satisfies the new institution.
- A notice period separate from the migration period. A three-month termination notice is useless if reissuing the cards takes six; set the two periods separately.
- Periodic data extracts, not just a final one. A copy of the ledger, balances, and customer files, delivered at regular intervals in a documented format, survives a freeze of the partner's systems.
- The KYC audit trail, not just the verdict. Documents, timestamps, screening list versions, and the decision log; otherwise the new institution will have to redo onboarding customer by customer.
- The right to communicate directly with end customers, written into the contract, including during a crisis and including when the institution is under a special representative.
- How exit costs are split, agreed in writing in advance; otherwise it gets negotiated at the worst moment with the party that has the least to lose.
- A fallback institution vetted before any incident, with a dated feasibility review; without it, the exit plan is a clause with no one to execute it.
- Data retention after the contract ends, aligned with the statutory retention period and enforceable against the partner's subcontractors.
Public data on these arrangements is limited. The number of active banking-as-a-service programs in the European Economic Area is not published, nor are their volumes, and no regulator publishes failure rates or average lifespans. National registers list agents but do not show which commercial program each entry belongs to, or what balances it holds. The figures circulating in the trade press come from the companies themselves, with no common definition of scope. Assessing a program therefore relies on public supervisory measures and the registers, not on these aggregates.