Reference🇪🇺 Payments in EuropeAdvanced⏱ 19 min read

🤝 Agents, distributors, and banking-as-a-service: who is liable for what

Agent registration and its legal effect, sharing KYC and monitoring, the line between agency and outsourcing, supervision of distributed programs, and exit planning

Agent, distributor, passported entity: what each status allows

A distributed payment program is an arrangement in which a licensed institution provides the payment services while another entity owns the relationship with the end customer. The two go to market under the second entity's brand. EU law does not define banking-as-a-service: the term appears in no directive and no public register. The law recognizes three positions: the licensed institution, the person acting on its behalf, and the entity to which an operational function is outsourced. Responsibilities follow from these three positions, never from the labels in the commercial contract. Words like “partner” or “program” have no legal effect in themselves.

An agent provides payment services on behalf of a payment institution or an e-money institution. It holds no license of its own. Instead, it is registered with the competent authority, which is a separate administrative step. A license entitles its holder to provide payment services in its own name, while registration only authorizes the agent to act on behalf of its principal. The agent's scope is capped by the services the principal is itself licensed to provide, and by those the mandate expressly covers. An agent therefore cannot provide any service its principal is not licensed for. The mandate can narrow the scope of the license, never widen it.

An e-money distributor is a natural or legal person that distributes and redeems e-money on behalf of the institution that issued it. Its position resembles an agent's, but its regime differs: it is not subject to any registration equivalent to the agent's. Article 3(4) of Directive 2009/110/EC requires member states to allow this delegation. Article 3(5), however, prohibits issuing e-money through agents. Distribution, loading, and redemption can therefore be handed to a third party, but issuance remains the licensed institution's own act. The holder's claim is always against the issuing institution, whatever brand the app displays.

🔑
Issuance cannot be delegated; distribution can
The line between issuance and distribution shapes the entire EU regime for distributed programs. An e-money institution may hand the sale, loading, and redemption of its e-money to a third party under Article 3(4) of Directive 2009/110/EC. Article 3(5) bars it from issuing through agents, while allowing it to provide payment services through agents under the conditions of Article 19 of PSD2. A partner that says it “issues cards” is describing an act the law assigns to the institution. The phrase is marketing language. A supervisor reviewing the arrangement attributes issuance to the license holder.
License typeWho holds the licenseWhat it allowsWhat it never allows
Payment institutionThe institution itself, granted by its home state authorityThe PSD2 Annex I services covered by its license, across the EEA once passportedTaking deposits in the banking sense; issuing e-money without a separate license
E-money institutionThe institution itselfIssuing e-money, plus the payment services covered by its licenseDelegating issuance itself to a third party
AgentThe principal institution, never the agentProviding, on the institution's behalf, the payment services covered by the mandate and listed in the registerIssuing e-money; providing a service the principal is not licensed to provide
E-money distributorThe issuing institutionDistributing and redeeming e-money issued by the institutionIssuing e-money, and thus creating the claim on the institution
The four statuses in a distributed program in the European Economic Area. Sources: Directive (EU) 2015/2366, Articles 5, 14, 19, and 20; Directive 2009/110/EC, Article 3.

Passporting extends a license granted in one member state to the entire European Economic Area. It works through two freedoms that trigger different obligations. The freedom to provide services lets an institution serve a market from its home state, with no local presence. The freedom of establishment covers branches, agents, and, for e-money institutions only, distributors. The second regime gives the host country's supervisor oversight rights that the first does not.

Regulators long drew the line between the two freedoms differently. The European Banking Authority's opinion of April 24, 2019 set a common reading. It covers institutions that use agents or distributors located in another member state, and followed the discovery of significant differences between national authorities. The opinion sets three criteria. The first is whether the task is occasional or regular and ongoing. The second is the overall length of the contractual relationship. The third is whether customers can use the service in their own member state. Under these criteria, an agent permanently based in a market and serving its customers falls under the freedom of establishment, while a one-off, time-limited activity falls under the freedom to provide services.

⚠️
The word “partner” says nothing about the applicable regime
A banking-as-a-service contract almost always calls the same signatory a partner, a distributor, a program, or a client. None of these four words has legal effect. The applicable regime follows from three verifiable facts. A third party that provides a payment service in the institution's name is an agent. One that distributes e-money issued by the institution is a distributor. One that performs a function for the institution, with no relationship with the user, falls under the outsourcing regime. A single contract often combines all three positions, each covering part of the flows.

The framework is being revised. On November 27, 2025, the European Parliament and the Council reached a provisional political agreement on the third Payment Services Directive and its accompanying regulation. The draft folds e-money institutions into payment institutions as a subcategory, repeals Directive 2009/110/EC, and brings the distributor regime closer to the agent regime. It requires an orderly wind-down plan covering the continuity of critical activities performed by outsourcing providers, agents, and distributors. The texts had not been published in the Official Journal as of September 2026; the final compromise texts of April 23, 2026, set a transposition period of 21 months after entry into force.

Registration, the public register, and agent passporting

Agent registration is the entry of the agent, by the competent authority and in a public register, as a party authorized to provide payment services in an institution's name. Article 19 of PSD2 governs it. An institution that intends to provide payment services through an agent submits an application to the competent authority of its home state. The authority verifies the information and refuses registration if it does not consider it accurate. The application covers the agent's identity, its internal anti-money laundering controls, the people who run it, and the exact scope of the mandate.

  • The agent's name and address, the only item everyone provides without being asked.
  • A description of the internal control mechanisms the agent uses to meet anti-money laundering and counter-terrorist financing obligations, to be updated without delay after any material change.
  • The identity of the agent's directors and managers responsible for providing payment services, with evidence that they are fit and proper when the agent is not itself a payment service provider.
  • The institution's payment services the agent is mandated for, listed service by service rather than by a blanket reference to the license.
  • The agent's unique identification code, where there is one.

The authority has two months from receiving the information to tell the institution whether the agent has been entered in the register. Article 19(2) attaches the legal effect to that entry. The agent may start providing payment services as soon as it is entered in the register, and has no right to do so before then. The authorization comes from the register, so the effective date of the commercial contract makes no difference. A program launched before registration has payment services provided by an unauthorized person, and the principal institution is liable for it.

⚠️
The register is authoritative; the contract is not
Three checks are made on the public register and nowhere else. The agent's presence is checked under the exact legal name that appears in the contract and on the end customer's screens. The principal linked to that entry must be the institution that signed the contract, not a sister company in the same group. The registered services are compared with what the program actually provides, since acquiring and issuing payment instruments are separate lines. A screenshot sent by the partner does not prove what the register showed on the date in question. The evidence a supervisor accepts is the institution's own direct lookup of the national register, dated and kept on file.

Two registers coexist, with different evidentiary weight. Article 14 of PSD2 requires each member state to keep a national public register, available online and updated without delay, that identifies the services covered by each license or registration. Article 15 tasks the European Banking Authority with a central electronic register that reproduces the national registers. The split of responsibilities between the two levels is explicit. The EBA answers only for faithfully reproducing what it receives, while the national authorities, which feed and update the data, are responsible for its accuracy.

2 months
time the home authority has to say whether the agent has been registered
Directive (EU) 2015/2366, Article 19(2)
3 months
time for a decision when the agent is engaged in another member state, from receipt of the complete application
Directive (EU) 2015/2366, Article 28
≈ 150 000
agents listed in the EU when the EBA central register launched
European Banking Authority, press release, March 18, 2019
Once a day
minimum frequency at which national authorities update the central register
European Banking Authority, press release, March 18, 2019

Engaging an agent in another member state triggers the Article 28 passporting procedure, which takes longer and involves more scrutiny. The home authority forwards the application to the host authority within one month of receiving it. The host authority then has one month to assess it and send its comments, particularly if it has reasonable grounds to suspect a money laundering or terrorist financing risk linked to the plan. The home authority decides within three months of receiving a complete application, enters the agent in the register, and then notifies its decision to the host authority and the institution.

Registering an agent in another member state
Institution
Submits the application to its home state authority
The information required by Article 19(1), plus the Article 28 information: target state, services concerned, and the agent's identity and internal controls.
Home authority
Forwards the application to the host authority
Within one month of receiving all the information (Article 28).
Host authority
Assesses and responds
One month to send its comments, in particular any reasonable grounds to suspect a money laundering or terrorist financing risk linked to the agent.
Home authority
Decides, registers, notifies
Three months from receipt of the complete application. Any disagreement with the host authority's assessment must be justified.
Agent
Starts operating in the host state
Registration gives the right to operate. The institution then notifies its home authority of the actual start date.

A central contact point is the person or entity an institution appoints in a host state to represent its network before the local authority. The obligation arises once the agent network reaches a significant size in that country. Two central contact point regimes coexist, with different legal bases and different thresholds. The first is an anti-money laundering regime, based on Article 45(9) of Directive (EU) 2015/849 and detailed in Delegated Regulation (EU) 2018/1108 of May 7, 2018. The second is prudential, based on Article 29 of PSD2 and detailed in Delegated Regulation (EU) 2020/1423 of March 14, 2019.

RegimeLegal basisTriggering thresholdsExpected functions
Anti-money launderingArticle 45(9) of Directive (EU) 2015/849; Delegated Regulation (EU) 2018/110810 or more establishments in the host state; or cumulative e-money distributed and redeemed, or cumulative value of transactions executed, above €3 million in a financial year or expected to reach that level; or information not available on requestEnsure the establishments comply with AML/CFT rules, report failures to head office, get them fixed, represent the institution before the authority, and facilitate on-site inspections
Prudential and supervisoryArticle 29 of Directive (EU) 2015/2366; Delegated Regulation (EU) 2020/142310 or more agents under the freedom of establishment; or total transaction value above €3 million with at least two agents; or more than 100,000 transactions in the last financial year with at least two agentsAct as the single reporting point for the host authority, handle communications with it, and facilitate its inspections
The two central contact point regimes in the host state and their thresholds

National transpositions add formalities that neither delegated regulation contains. Italy offers the best-documented example. Agents providing payment services in Italy on behalf of an institution from another member state must report their activity to the OAM (Organismo Agenti e Mediatori, Italy's register of financial agents and credit brokers). The report covers the start of activity, updated information, changes, and termination. It is sent by certified email, under Article 128-quater, paragraph 7, of the Testo Unico Bancario. These agents are not entered in the special section of the list reserved for agents of Italian institutions. That does not exempt them from reporting, which rests on a separate legal basis.

Who does KYC, who monitors, and who stays liable

Article 20 of PSD2 establishes the principal institution's full liability. Member states must require the payment institution to remain fully liable for all acts of its employees and of any agent, branch, or entity to which activities are outsourced. That liability covers the entire scope, however the parties divide tasks between them. No agreement can transfer it. A contract can allocate the workload, financial compensation, and burden of proof among its signatories. But before the supervisor, only the institution answers for failings found at its agent.

🔑
What an indemnity clause cannot do
A clause that makes the partner bear the financial consequences of an anti-money laundering failure has real effect between the two signatories and before a civil court. It has no effect before the supervisor, which is not a party to the contract and applies Article 20 of PSD2. Administrative measures, injunctions, business restrictions, and license withdrawal fall on the institution. Recovering compensation from the partner makes good the financial loss, but it does not undo the administrative measure or restore a withdrawn license. The two proceedings run independently, before different courts and authorities.

The duty to monitor agents starts with the license application, before any agent is registered. Article 5(1)(l) of PSD2 requires the applicant to describe its organizational structure, including its planned use of agents and branches. It must also describe the off-site and on-site checks it commits to performing on them at least once a year. That frequency is written into the EU text itself. An institution with no enforceable annual control plan departs from the organization it described to obtain its license. The gap is therefore more than an operational weakness: it concerns the very description on which the license was granted.

Know your customer (KYC) covers collecting the user's identity data, verifying it, and classifying the customer by risk level. The split between the institution and its partner almost always follows the same pattern. The partner runs the interface, collects ID documents, records the verification video, and absorbs the drop-off rate. The institution is the obliged entity: it decides whether to onboard, sets the risk classification, rules on alerts, and signs the suspicious activity report. The setup holds as long as the institution can access the documents the partner collected. It breaks down as soon as the institution sees only an aggregated status, because its decision then becomes a formality and its monitoring rests on the partner's word.

  • Ongoing access to the document itself, not just to the result of the check. The raw customer file, images, timestamps, and decision log must be viewable from the institution's systems.
  • On-site audit rights, exercisable without long notice and extended to the partner's subcontractors through flow-down clauses.
  • The right to rerun screening on the partner's customer base with the institution's own tools and lists, to test something other than the partner's compliance with its own rules.
  • Direct access for the supervisor and, where one exists, the resolution authority, written into the contract and enforceable against subcontractors.
  • Full return of data on exit, in a usable format, within a set deadline, with retention guaranteed for the statutory retention period.
  • No subcontracting of data collection without prior written consent; otherwise the chain extends beyond the reach of the original contract.

German supervision offers a documented precedent of measures against an institution whose oversight of its partner network was found deficient. On December 16, 2022, BaFin ordered Solaris SE to ensure proper business organization in risk management and anti-money laundering, a measure that became final on January 25, 2023. The order barred the institution from entering into new cooperation partnerships without the supervisor's prior approval, and a special representative was appointed under Section 45c of the Kreditwesengesetz (German Banking Act). A second order, published on July 12, 2024, targeted failings in anti-money laundering, regulatory reporting, outsourcing management, and IT systems. The special representative's mandate was extended.

⚠️
A monthly report is not proof of monitoring
The standard documentation for a distributed program includes a monthly dashboard, an onboarding approval rate, an alert count, and an average handling time. The agent produces these figures, and they describe its own work. They therefore do not show that the institution monitored its agent. Evidence of monitoring bears the trace of work done by the institution itself: a sample of files re-reviewed by its own teams, a measured gap between the partner's risk classification and its own, or a dated on-site inspection with its findings and follow-up. An inspection report separates the two kinds of evidence and accepts only the second as proof of monitoring.
At least once a year
off-site and on-site checks the applicant commits to performing on its agents and branches
Directive (EU) 2015/2366, Article 5(1)(l)
December 16, 2022
BaFin order barring Solaris SE from any new cooperation partnership without the supervisor's prior approval
BaFin; the measure became final on January 25, 2023
10 business days
written notice Modulr committed to giving the FCA before taking on a new agent or distributor, outside the EEA
Financial Conduct Authority, restriction lifted in July 2024

Agency or outsourcing: two regimes, two sets of obligations

Outsourcing means using a third party to perform an operational function the institution would otherwise perform itself. An agency mandate puts the third party in a position to provide the payment service to the user, in the institution's name and on its behalf, and the user must be told so. Article 19 of PSD2 deals with agents, branches, and outsourcing providers together. Yet the obligations attached to each differ on almost every point. The dividing line between the two regimes is the relationship with the payment service user. An outsourcing provider performs a function for the institution without providing the service itself and without any payment relationship with the user.

IssueAgent or distributorOutsourcing provider
Relationship with the userProvides the service in the institution's name and tells the user it is acting on the institution's behalfNo payment relationship with the user
Filing with the supervisorPrior registration of the agent, which is a precondition: activity starts upon registration. Directive 2009/110/EC imposes no equivalent registration for distributorsNotice to the home authority, with no entry in the public register
Public visibilityThe agent appears in the national register and the EBA central register, which has no “distributor” categoryDoes not appear in any public register
Cross-border activityTriggers the Article 28 passporting procedure and, above the thresholds, a central contact pointDoes not in itself create an establishment in the provider's country
Classification to watchExact scope of the mandated services, service by serviceWhether the outsourced operational function is important
LiabilityThe institution remains fully liable (Article 20)The institution remains fully liable (Article 20)
How the rules differ when the third party acts under a mandate rather than performing an outsourced function. Source: Directive (EU) 2015/2366, Articles 5, 14, 19, 20, and 28; guidelines EBA/GL/2019/02.

PSD2 Article 19(6) defines an important operational function by the consequences of its failure rather than by its nature. A function is important if a defect or failure in its performance would seriously impair one of three things: the institution's ability to keep meeting its license conditions, its financial performance, or the soundness and continuity of its payment services. The same paragraph sets four cumulative conditions. Senior management cannot delegate its responsibility. The relationship with users and the obligations toward them remain unchanged. The license conditions are not undermined. And none of those conditions is removed or modified.

The European Banking Authority's guidelines EBA/GL/2019/02 were published on February 25, 2019, and have applied since September 30, 2019. ⚠️ They are due to be replaced: on September 18, 2026, the European Banking Authority published its final guidelines on managing third-party risk for non-ICT services. These align the framework with DORA, focus the obligations on critical or important functions, and provide for a two-year transition period. The application date has not yet been set, as the text awaits translation into the EU's official languages. The current guidelines extend to payment and e-money institutions an outsourcing framework that the earlier guidelines of CEBS, the EBA's predecessor, reserved for credit institutions and investment firms. They require a risk assessment and due diligence before contracting, then a written contract with minimum content. They also require a register of all outsourcing arrangements that flags those covering critical or important functions. On top of this come audit and access rights for both the institution and the authorities, rules on chain outsourcing, and a documented exit strategy. The register is the first document a supervisor asks for in an inspection, because it lists all outsourcing arrangements in one place and flags those covering critical or important functions.

ℹ️
What the guidelines do not treat as outsourcing
The EBA/GL/2019/02 guidelines expressly exclude several types of arrangements, which keeps irrelevant lines out of the register. Global network infrastructures such as Visa and Mastercard are not covered. Global financial messaging infrastructures, clearing and settlement arrangements between a clearing house and its members, correspondent banking, and market information services are excluded in the same way. What these exclusions share is the nature of the service. A service the institution would never perform itself does not count as an outsourced function, whereas a card processing platform, which it would otherwise run itself, does.

Regulation (EU) 2022/2554, known as DORA, which has applied to payment and e-money institutions since January 17, 2025, has taken over the IT side. Arrangements with third-party ICT service providers now fall under its register of information and its own concept of critical or important functions. It has its own contractual requirements and resilience testing. The outsourcing guidelines still apply to arrangements that do not involve IT services. In 2025, the European Banking Authority consulted on extending this framework to all third-party arrangements outside DORA, a sign that the boundary is not yet settled.

⚠️
The same partner often falls under both regimes at once
The partner in a distributed program sells to the end customer, which makes it an agent or a distributor. It also almost always hosts part of the institution's operational chain: first-line customer service, transaction monitoring tools, the onboarding decision engine. That second role is outsourcing, with its own register, minimum contract content, audit rights, and exit plan. A single contract that documents only the first role leaves the second without a written basis. An examiner spots this gap by comparing the outsourcing register with the description of the flows. Fixing it after the fact means renegotiating, with a partner already in place, the audit, subcontracting, and exit clauses missing from the original contract.

When a program shuts down, and what the end customer is left with

Supervisors act on a distributed program in stages, and the first ones go unnoticed by end customers. The first stage is an order to remediate, with deadlines, sometimes periodic penalty payments, and a monitor appointed by the authority to check compliance. The second is a freeze on onboarding, which may target new customers, new agents and distributors, or new partnerships. The third is license withdrawal, whose grounds Article 13 of PSD2 lists, from not using the license for 12 months to posing a threat to the stability of the payment system.

December 16, 2022
BaFin puts Solaris SE under restrictions
Order to ensure proper business organization in risk management and anti-money laundering, ban on new cooperation partnerships without prior approval, and appointment of a special representative under Section 45c of the Kreditwesengesetz. The measure became final on January 25, 2023 (BaFin).
February 2023
Bank of Lithuania freezes onboarding at UAB PayrNet
The e-money institution is barred from establishing business relationships with new customers, over serious and systematic breaches of the anti-money laundering law (Lietuvos bankas).
June 22, 2023
UAB PayrNet loses its license
The Bank of Lithuania revokes the firm's e-money institution license for serious, systematic, and multiple breaches of the laws on e-money, anti-money laundering, and payments. The institution must return its customers' funds within the set deadline, and the central bank announces it will petition the court for bankruptcy (Lietuvos bankas).
October 2023
FCA restricts Modulr (outside the EEA)
The UK regulator bars onboarding of new partner clients, agents, and distributors until oversight arrangements are brought up to standard (FCA).
July 12, 2024
BaFin issues a second order against Solaris SE
Failings in anti-money laundering, regulatory reporting, outsourcing management, and IT systems. The mandate of the special representative appointed in late 2022 is extended (BaFin).
July 2024
FCA lifts the restriction on Modulr
The restriction is lifted. The institution commits to notifying the FCA in writing at least 10 business days before taking on any new agent or distributor (FCA).
November 27, 2025
Provisional political agreement on PSD3 and the Payment Services Regulation
E-money institutions become a subcategory of payment institutions, and distributors move closer to the agent regime. An orderly wind-down plan is required, covering critical activities performed by providers, agents, and distributors. The texts were still unpublished in mid-2026.

The Lithuanian timeline shows how long it takes from the first public measure to the institution's disappearance. The onboarding freeze came in February 2023 and the license withdrawal on June 22, 2023, followed by bankruptcy proceedings. Four months separate the freeze from the withdrawal. The freeze was public, so the hosted programs had a warning before the final decision. Yet even an exit plan launched at that point runs behind the technical timeline, because reissuing cards takes months, not weeks.

⚠️
Licenses are withdrawn from institutions, not programs
Agents and distributors hold no license, so no withdrawal decision targets them directly. But when the principal institution loses its license, the agent loses, on the same day, its right to operate, its issuer, its IBANs, its BINs, and access to its own customers. End customers' funds are protected at the institution through safeguarding, and are returned under the proceedings opened against it. The brand end customers see is the agent's, while the loss and its handling belong to the institution. End customers therefore complain to the agent, whose brand takes the reputational hit for a failure it did not cause.

Moving a program to another institution means completely reissuing its instruments and account details. IBANs assigned under the institution's BIC do not follow the program, and neither do virtual IBANs allocated from its ranges. BIN ranges depend on the issuer's scheme license, so they stay with the issuer. The KYC file is portable in theory, but whether the new institution accepts it depends on the quality of the audit trail, not on a contract clause. A program that changes institutions changes its bank details, card numbers, and customer contract. The only things that survive the migration without being rebuilt are the commercial relationship, and the KYC file if its audit trail satisfies the new institution.

  • A notice period separate from the migration period. A three-month termination notice is useless if reissuing the cards takes six; set the two periods separately.
  • Periodic data extracts, not just a final one. A copy of the ledger, balances, and customer files, delivered at regular intervals in a documented format, survives a freeze of the partner's systems.
  • The KYC audit trail, not just the verdict. Documents, timestamps, screening list versions, and the decision log; otherwise the new institution will have to redo onboarding customer by customer.
  • The right to communicate directly with end customers, written into the contract, including during a crisis and including when the institution is under a special representative.
  • How exit costs are split, agreed in writing in advance; otherwise it gets negotiated at the worst moment with the party that has the least to lose.
  • A fallback institution vetted before any incident, with a dated feasibility review; without it, the exit plan is a clause with no one to execute it.
  • Data retention after the contract ends, aligned with the statutory retention period and enforceable against the partner's subcontractors.

Public data on these arrangements is limited. The number of active banking-as-a-service programs in the European Economic Area is not published, nor are their volumes, and no regulator publishes failure rates or average lifespans. National registers list agents but do not show which commercial program each entry belongs to, or what balances it holds. The figures circulating in the trade press come from the companies themselves, with no common definition of scope. Assessing a program therefore relies on public supervisory measures and the registers, not on these aggregates.

✅
Six questions that decide a distributed program
The identity of the license holder is checked on the register: the entity signing the contract must be the one listed there. The partner's position is determined flow by flow (agent, distributor, or outsourcing provider), and all three can coexist. The registration is checked for its existence and for its scope, compared with the services actually provided. The onboarding decision belongs to the institution, which must have access to the documents collected, not just the partner's verdict. The annual control plan is checked for its existence, then for the findings it produced and the follow-up they received. The exit plan is signed before launch, with its deadlines, formats, and fallback institution. Five good answers out of six are not enough, because the point skipped during selection is the one that surfaces the day a license is withdrawn.