Structuring Under the CBUAE RPSCS Regime (2026 Edition)
By CRYPTOVERSE Legal Consultancy
Advising Fintech, Payment Institutions & Cross-Border Operators on CBUAE Licensing & Capital Architecture
Three Business Models, Three Risk Profiles — One Regulator
In the UAE’s rapidly evolving digital payment ecosystem, three business models dominate the fintech landscape:
- Merchant Acquiring
- Cross-Border Remittance
- Payment Aggregation
At first glance, they appear commercially similar. They all “move money.”
But under the Retail Payment Services and Card Schemes (RPSCS) Regulation issued by the Central Bank of the UAE (CBUAE), they are treated very differently.
Each model carries:
- A distinct risk profile
- Different capital implications
- Unique AML exposure
- Varying settlement risk
- Different supervisory intensity
Misclassification or poor structuring can result in:
- Licence delays
- Capital escalation
- Regulatory reclassification
- Supervisory intervention
- Banking friction
This guide provides a deep structural analysis of how to design, license, and scale merchant acquiring, remittance, and aggregation businesses under the RPSCS framework.
If you are building payment infrastructure in the UAE, this is essential reading.
Part I — Understanding the RPSCS Risk Lens
Before analysing each model individually, we must understand how the CBUAE views payment risk.
Under RPSCS, the regulator evaluates:
- Operational risk
- Settlement exposure
- AML/CFT risk
- Cross-border exposure
- Merchant risk
- Chargeback liability
- Systemic impact
Capital and licence categories are tied to risk creation, not revenue.
The core supervisory question is:
“Does this business create material risk to the payment ecosystem?”
Merchant acquiring, remittance, and aggregation answer that question differently.
Part II — Merchant Acquiring: High Settlement & Scheme Exposure
Merchant acquiring is one of the most systemically significant payment functions.
It involves:
- Contracting merchants
- Enabling card acceptance
- Settling funds to merchants
- Managing chargebacks
- Bearing scheme compliance obligations
Under RPSCS, merchant acquiring typically falls within Category I scope due to its risk intensity.
Why Merchant Acquiring Is Prudentially Sensitive
Acquirers assume:
- Settlement timing risk
- Chargeback liability
- Fraud exposure
- Merchant default risk
- Card scheme compliance obligations
If an acquirer fails:
- Merchants suffer
- Card schemes react
- Consumers are impacted
- Payment ecosystem stability is tested
This systemic footprint justifies higher capital and governance scrutiny.
Capital Implications
Merchant acquiring generally aligns with:
Category I capital range (~ AED 1.5m–3m).
However, capital expectations may increase based on:
- Transaction volume
- Merchant portfolio risk
- Chargeback ratios
- Fraud exposure
- Settlement cycle length
Capital is not merely a threshold, it is a buffer against operational shock.
Part III — Cross-Border Remittance: AML & Corridor Risk
Remittance businesses present a different risk profile.
Unlike acquiring, their core risk is not chargeback — it is AML and sanctions exposure.
Cross-border PSPs facilitate:
- Outbound transfers
- Inbound transfers
- Corridor-specific payouts
- Correspondent relationships
Under RPSCS, cross-border activity generally falls within Category II or Category I, depending on scope.
Why Remittance Is High-Scrutiny
Remittance operators face:
- Sanctions compliance risk
- High-risk jurisdiction exposure
- AML transaction monitoring complexity
- Correspondent banking risk
- Currency settlement exposure
Supervisory expectations are stringent because cross-border flows can:
- Facilitate financial crime
- Trigger international scrutiny
- Impact correspondent banking access
AML maturity is critical.
Capital Implications
Category II capital (~ AED 1m–2m) is typical for remittance operators.
However, capital adequacy is assessed alongside:
- Corridor risk profile
- Transaction velocity
- Monitoring sophistication
- Fraud metrics
Rapid volume growth without AML scaling can trigger supervisory concerns.
Part IV — Payment Aggregation: The Hybrid Model
Payment aggregators sit between gateways and acquirers.
They:
- Aggregate merchant transactions
- Operate under master acquiring arrangements
- Facilitate onboarding of smaller merchants
- Manage merchant-level risk
Aggregation may initially fall within Category III, but can escalate depending on structure.
The Structural Risk in Aggregation
Aggregators may assume:
- Merchant onboarding risk
- Sub-merchant compliance risk
- Fraud exposure
- Settlement timing exposure
If the aggregator assumes settlement liability directly, risk profile increases.
If it merely facilitates technical routing under acquirer oversight, risk may remain lower.
Structuring matters significantly.
Part V — Comparing the Three Models
| Feature | Merchant Acquiring | Remittance | Aggregation |
| Primary Risk | Chargeback & fraud | AML & sanctions | Merchant risk |
| Typical Category | I | II or I | III–I |
| Capital Intensity | Moderate | Moderate | Variable |
| Settlement Risk | High | Moderate | Variable |
| AML Exposure | Moderate | High | Moderate |
| Cross-Border Impact | Indirect | Direct | Indirect |
Each model triggers different supervisory questions.
Part VI — Structuring Merchant Acquiring Under RPSCS
To structure merchant acquiring properly:
- Determine direct vs indirect acquiring model
- Assess scheme relationships
- Define settlement cycle
- Implement merchant due diligence
- Model chargeback risk
- Build fraud monitoring framework
- Design capital buffer
- Structure governance
Chargeback modelling is particularly critical.
High chargeback ratios can trigger scheme penalties and regulatory scrutiny.
Part VII — Structuring Remittance Under RPSCS
Remittance structuring requires:
- Corridor risk assessment
- Sanctions screening framework
- Transaction monitoring engine
- Correspondent due diligence
- Liquidity planning
- Capital buffer modelling
- Customer onboarding controls
Regulators will test AML capability rigorously.
AML weakness is the most common reason for delay.
Part VIII — Structuring Payment Aggregation Under RPSCS
Aggregation structuring depends on:
- Whether funds are held
- Whether settlement risk is assumed
- Merchant onboarding control level
- Fraud exposure
To maintain Category III positioning:
- Avoid assuming acquiring liability
- Maintain limited settlement exposure
- Document merchant due diligence
- Keep capital buffer conservative
If aggregation begins to resemble acquiring, reclassification may occur.
Part IX — Escalation Triggers Across Models
Merchant acquiring escalation may occur if:
- Merchant portfolio becomes high-risk
- Chargebacks exceed thresholds
- Cross-border merchants increase
Remittance escalation may occur if:
- New high-risk corridors added
- Volume spikes rapidly
- AML systems lag growth
Aggregation escalation may occur if:
- Direct settlement liability assumed
- Merchant risk concentrated
- Cross-border exposure introduced
Expansion must be pre-modelled.
Part X — Capital Stress Testing Across Models
Merchant Acquiring Stress
- Fraud spike
- Chargeback wave
- Merchant default
Capital absorbs operational losses.
Remittance Stress
- Sanctions breach
- Corridor freeze
- Liquidity mismatch
Capital supports operational continuity.
Aggregation Stress
- Merchant fraud cluster
- Settlement timing disruption
- Chargeback surge
Capital buffers protect solvency.
Stress testing should simulate 12–24 month downside scenarios.
Part XI — Governance Expectations
Across all three models, the CBUAE expects:
- Competent board
- Compliance officer
- MLRO
- Independent oversight
- Risk management function
- Internal controls
Merchant acquiring may require additional scheme compliance governance.
Remittance requires AML-heavy governance.
Aggregation requires merchant risk oversight.
Part XII — Hybrid Models: The Structural Risk Trap
Many fintech platforms combine:
- Wallet balances (SVF)
- Merchant acquiring
- Remittance
- Stablecoin settlement
Without clear entity structuring, capital exposure multiplies.
Hybrid structuring may benefit from:
- Separate entities
- Ring-fenced capital
- Distinct governance oversight
However, structuring must align with regulatory approval.
Part XIII — Investor & Banking Considerations
Banks assess:
- AML sophistication (remittance)
- Chargeback exposure (acquiring)
- Merchant risk controls (aggregation)
Investors assess:
- Capital efficiency
- Regulatory scalability
- Escalation risk
Transparent capital modelling enhances credibility.
Part XIV — Pre-Application Structuring Strategy
Before applying, founders should:
- Confirm precise activity scope
- Model 36-month transaction growth
- Forecast category escalation risk
- Prepare AML documentation
- Draft merchant onboarding policy
- Model capital buffer
- Engage regulator strategically
Applying under the wrong category creates costly delays.
Part XV — Designing for Regulatory Elasticity
Regulatory elasticity means:
You can expand services without sudden capital shock.
Best practices:
- Overcapitalise early
- Model expansion roadmap
- Maintain compliance staffing buffer
- Pre-plan cross-border expansion
- Maintain proactive regulator communication
Growth should not surprise the regulator.
Structuring Determines Stability
Merchant acquiring, remittance, and aggregation may appear commercially similar.
But under RPSCS:
- They are risk-distinct.
- They are capital-distinct.
- They are supervision-distinct.
The most successful payment institutions:
- Classify correctly
- Model capital prudently
- Build AML maturity early
- Structure governance robustly
- Design for scale
Regulatory structure is a competitive advantage.
Why CRYPTOVERSE Legal
We advise fintech and payment operators on:
- RPSCS classification
- Merchant acquiring structuring
- Remittance corridor modelling
- Aggregation risk design
- Capital forecasting
- Regulatory engagement strategy
- Post-licensing compliance architecture
We design payment infrastructure aligned with supervisory expectations.
Key Takeaways
- Merchant acquiring carries settlement & chargeback risk.
- Remittance carries AML & corridor risk.
- Aggregation carries merchant & fraud risk.
- Capital is category-based but risk-sensitive.
- Expansion can trigger reclassification.
- Proper structuring prevents capital shock.
- Regulatory elasticity enables sustainable growth.
Legal Disclaimer: This article is provided for informational purposes only and does not constitute legal advice. Licence classification, capital requirements, and supervisory obligations under the CBUAE RPSCS Regulation depend on the specific operational model, transaction scope, governance structure, and risk exposure of each applicant. Formal legal analysis should be undertaken prior to regulatory engagement or expansion decisions.
FAQs
1. What is CBUAE RPSCS?
It is the UAE framework regulating retail payment services and card schemes.
2. Does merchant acquiring require a CBUAE licence?
Yes, regulated merchant acquiring activities generally require CBUAE authorisation.
3. Is remittance regulated by the CBUAE?
Yes, cross-border remittance is subject to applicable CBUAE licensing and AML/CFT requirements.
4. Can payment aggregators require licensing?
Yes. Licensing depends on the aggregator’s actual activities, settlement role and risk exposure.
5. What affects CBUAE payment licensing capital requirements?
Capital requirements depend on the applicable licence category, activities and overall risk profile.