How to Start an Online Casino That Accepts Real Money for Wagering
Whether operating as an Independent Sales Organization (ISO) or a Payment Service Provider (PSP), companies must sequence federal registrations (such as FinCEN MSB), state Money Transmitter Licenses (MTLs), and international authorizations (PSD2/PSD3 in the EU) correctly while maintaining robust compliance, fraud prevention, and gateway technology stacks.
Starting a payment processing company means building the financial infrastructure that sits between merchants and their customers’ banks. You are not selling a product. You are selling trust, uptime, and regulatory compliance. Get any one of those wrong and accounts shut down, sometimes overnight.
The full path covers choosing your business model, securing the licenses you actually need, picking the right technology stack, and navigating the vertical-specific rules that apply if your merchants include online casinos, crypto platforms, or other high-risk businesses.
LegalBison helps payment processors and fintech founders with entity structuring, licensing strategy, and sponsor bank introductions. Building a payment processing company requires navigating licensing, technology, and compliance in the right sequence.
A payment processing company moves money from a buyer to a seller. The mechanics involve four parties: the cardholder, the merchant, the acquiring bank (your sponsor bank), and the issuing bank (the cardholder’s bank). You sit in the middle, authorizing transactions, settling funds, and handling disputes.
The business model is fee-based. You earn a small percentage of every transaction you process, plus monthly fees, chargeback fees, and sometimes setup fees. Margins are thin per transaction but scale with volume. A company processing USD 100 million per month at a 0.5% margin earns USD 500,000 per month before operating costs.
The barrier to entry is not technology. It is bank relationships and licensing. Any competent developer can build a payment gateway. Getting a sponsor bank to underwrite your program and a regulator to license your entity is the hard part.
The structural choice at the foundation of your business determines your capital requirements, your bank relationships, your liability profile, and your ceiling for growth. The two primary models are ISO/MSP registration and PSP operation. They are not interchangeable.
An Independent Sales Organization (ISO) or Merchant Service Provider (MSP) acts as an agent for a sponsoring bank. You recruit merchants, onboard them under the sponsor bank’s acquiring relationship, and earn a share of the processing fees. The sponsor bank holds the merchant agreement, carries the regulatory liability, and sets the underwriting standards.
This model requires less capital upfront. You do not need your own processing infrastructure or bank license. Your revenue is a split of the discount rate. The tradeoff is that you depend entirely on the sponsor bank’s policies, pricing, and risk appetite. If the bank exits your merchant category, you lose those accounts.
For new entrants, the ISO model is generally the smarter starting point. You build processing history, learn merchant underwriting, and develop operational credibility before taking on direct liability.
A Payment Service Provider (PSP) aggregates merchants under a single master merchant account. Merchants board faster because they are sub-merchants of the PSP rather than direct accounts with the bank. The PSP owns the technology stack, handles settlement, and manages compliance. See our PSP licensing guide for jurisdiction-specific authorization requirements.
The tradeoff is liability. When a sub-merchant has a chargeback problem, it is the PSP’s ratio that suffers. For high-risk verticals like iGaming, this concentration risk is significant. One high-volume merchant with a chargeback spike can blow past card network thresholds overnight.
PSPs need more capital, stronger technology, and deeper bank relationships. The upside is higher margins, direct control over the merchant experience, and the ability to set your own underwriting standards within the sponsor bank’s guidelines.
Start as an ISO if you are new to payments, have limited capital, or want to validate a merchant niche before investing in infrastructure. Move to a PSP model once you have processing history, a portfolio of merchants, and the operational maturity to manage portfolio-level risk.
For iGaming and crypto verticals, the PSP model requires a sponsor bank that explicitly supports those categories. Most mainstream banks do not. You need specialized banking relationships, which often means longer onboarding timelines and higher reserves. See our guides to iGaming licensing and crypto licensing for vertical-specific requirements.
Payment processing licensing is layered. Federal registration comes first. State licenses come next. Vertical-specific permits come after that. The order matters because each layer depends on the one before it.
In the United States, every payment processor must register as a Money Services Business (MSB) with the Financial Crimes Enforcement Network (FinCEN). This is not optional. Registration must be filed within 180 days of establishment. The process is straightforward: submit FinCEN Form 107, provide basic business information, and receive your registration. The filing itself is free.
MSB registration covers your federal AML (anti-money laundering) obligations. You must appoint a compliance officer, write an AML program, file Suspicious Activity Reports (SARs) when required, and maintain records for five years. For a deeper look at US licensing structures, see our guide to MSB versus MTL licensing.
After federal registration, you need state-by-state Money Transmitter Licenses (MTLs) in each state where you operate. This is the expensive and time-consuming part. Requirements vary by state. Some states require minimum net worth of USD 100,000 to USD 1 million. Surety bond requirements range from USD 25,000 to USD 7 million depending on state and processing volume. Application fees range from USD 500 to USD 10,000 per state. Annual renewal fees are similar.
Getting licensed in all 50 states can take 12 to 24 months and cost USD 200,000 to USD 500,000 or more in legal fees, bonds, and net worth requirements. Most processors start with a handful of states and expand over time.
Shortcuts exist but come with risk. The “Agent of the Payee” model lets you operate under a licensed partner’s coverage. “For Benefit Of” (FBO) bank accounts let the sponsor bank’s license cover the operation. These structures work for early-stage processors but create dependency on the partner. Build toward your own licenses as quickly as your capital allows.
In the European Union, payment services are regulated under the Payment Services Directive 2 (PSD2). Payment institutions (PIs) and electronic money institutions (EMIs) apply for authorization with their home national competent authority. Once authorized, they can passport across all 27 EU member states. See our EMI licensing guide for capital requirements and application steps across key EU jurisdictions.
PSD3 is the successor framework. Political agreement was reached in November 2025, with Council texts published in April 2026. Adoption is pending. PSD3 applies approximately 21 months after entry into force. The transition period runs about 21 months, and existing licensees are grandfathered. Expect PSD3 to be operational around 2028.
The UK operates under the Financial Conduct Authority (FCA). Authorization as an authorized payment institution or electronic money institution takes 3 to 12 months. The FCA requires a minimum of EUR 20,000 to EUR 125,000 in initial capital depending on the license type, a detailed business plan, AML policies, and fit-and-proper assessments for all directors and shareholders.
Canada requires registration under the Retail Payment Activities Act (RPAA) for payment service providers. Registration costs CAD 2,500 (non-refundable). The Bank of Canada oversees the registration process and requires risk-management frameworks, safeguarding mechanisms for client funds, and compliance programs. The RPAA framework came into effect September 8, 2025.
Singapore regulates payment services under the Payment Services Act 2019 (PSA). A Standard Payment Institution (SPI) license applies if your monthly transaction volume is below SGD 3 million for any single service or SGD 6 million for two or more services, and your e-money float is below SGD 5 million. Above those thresholds, you need a Major Payment Institution (MPI) license. MAS application decisions take up to 12 months.
Licensing gets you in the door. Compliance keeps you open. Payment processors face continuous obligations that scale with volume and jurisdiction.
Every payment processor must maintain an anti-money laundering program. This includes customer identification procedures (know your customer, or KYC), transaction monitoring, suspicious activity reporting, and record retention. In the EU, the Anti-Money Laundering Regulation (AMLR) applies from July 2027, replacing the current directive-based framework with directly applicable rules.
KYC requirements vary by risk level. Low-risk merchants need basic identity verification. High-risk merchants, including iGaming operators and crypto platforms, require enhanced due diligence: source of funds verification, beneficial ownership identification, and ongoing monitoring.
Visa and Mastercard set their own rules that payment processors must follow. Chargeback ratios matter. Visa’s Acquirer Monitoring Program (VAMP) triggers at 1,500 combined fraud reports (TC40) and disputes (TC15) per month and a ratio of 1.5% of settled transactions. Mastercard’s Exceeding Chargeback Program triggers at 100 chargebacks and 1.5% per month. Exceeding these thresholds results in fines and potential termination.
Transaction Integrity Compliance (TIC) and the Transaction Processing Excellence (TPE) framework govern retry logic, duplicate transaction prevention, and routing accuracy. Violations result in scheme fines.
PCI DSS (Payment Card Industry Data Security Standard) compliance is mandatory for any entity that stores, processes, or transmits cardholder data. Level 1 merchants (processing over 6 million transactions per year) must complete an annual on-site audit by a Qualified Security Assessor (QSA). Smaller processors can complete a Self-Assessment Questionnaire (SAQ). Non-compliance results in fines of USD 5,000 to USD 100,000 per month.
You need a payment gateway capable of authorizing, routing, and settling transactions. There are three paths.
The most expensive and slowest option. A production-grade payment gateway with routing logic, tokenization, 3D Secure authentication, fraud tooling, and reporting infrastructure runs USD 500,000 to USD 2 million or more in development cost before you process a single live transaction. The advantage is full control. For processors expecting significant volume and a long operational runway, proprietary infrastructure eventually makes sense. At entry scale, it usually does not.
You brand an existing platform as your own. You pay monthly platform fees and per-transaction fees. The tradeoff is dependence on the provider’s reliability, PCI DSS compliance, and willingness to support your merchant categories. Several white-label providers have exited high-risk verticals due to their own bank relationships restricting those categories. Verify gaming and crypto support before signing.
This option makes the most sense for processors handling multiple acquirer relationships or high-risk verticals. An orchestration layer sits above your acquiring relationships and routes transactions intelligently across multiple processors. If your primary acquirer rejects a transaction, the orchestration layer cascades the attempt to a secondary acquirer in real time.
Every transaction must carry a unique key so retry logic cannot submit the same charge twice. Mastercard’s TPE framework limits retry attempts and timing. Network tokenization (tokens issued by Visa or Mastercard at the network level) solves the portability problem when retrying across different acquirers. For iGaming platforms with high retry scenarios, network tokenization is worth the integration cost.
Payment processing for iGaming and crypto platforms follows the same structural rules as general payment processing but with additional layers of regulatory complexity.
Online casinos and sportsbooks are classified as high-risk merchants. Banks view gambling as high-risk because of regulatory fragmentation, chargeback patterns, and reputational concerns. Merchant Category Code (MCC) 7995 triggers caution across the card network ecosystem.
You need a sponsor bank that explicitly supports gaming merchants. Most mainstream banks do not. Specialized high-risk banks and embedded finance platforms that focus on regulated gaming markets are the realistic option. Come prepared with a documented merchant onboarding policy, AML/KYC procedures, a chargeback management plan, and a clear description of the merchant categories you intend to serve. Budget four to eight months for sponsor bank due diligence.
If you work with regulated casinos, you often need a gaming supplier license in addition to your payment processing licenses. These licenses require deep background checks, financial history reviews, and fingerprinting. The process typically takes 6 to 18 months.
Chargeback management is critical across all verticals. Visa’s Acquirer Monitoring Program (VAMP) triggers at 1,500 combined fraud reports (TC40) and disputes (TC15) per month and a ratio of 1.5% of settled transactions. Mastercard’s Exceeding Chargeback Program triggers at 100 chargebacks and 1.5% per month. Exceeding these thresholds results in fines and potential termination. Aim to keep chargebacks below 0.75% as a buffer.
Crypto payment processing operates in a different regulatory framework. If your platform converts crypto to fiat at the point of sale, you are a money transmitter in the US and need FinCEN MSB registration plus state MTLs. If you only facilitate crypto-to-crypto transfers, the licensing requirements may differ by jurisdiction.
In the EU, MiCA (Markets in Crypto-Assets Regulation) applies from December 30, 2024. Crypto-asset service providers (CASPs) that handle custody, exchange, or transfer of crypto-assets need authorization. The transition period for existing CASPs closed July 1, 2026.
Travel Rule compliance (Regulation 2023/1113 in the EU, FinCEN rules in the US) requires that payment processors transmit originator and beneficiary information for crypto transfers above EUR 1,000 (EU) or USD 3,000 (US). Self-hosted wallet transfers are included in the EU scope.
Payment processing has enough interdependencies that sequencing matters. Getting the order wrong wastes months. If you are figuring out how to start a payment processing company, follow this sequence.
Which merchants do you want to serve? E-commerce retailers? Restaurants? iGaming operators? Crypto exchanges? Each category carries a different regulatory profile, chargeback risk profile, and bank relationship requirement. Your merchant scope determines everything downstream.
ISO or PSP? For most new entrants, the ISO model under a sponsor bank with experience in your target vertical is the starting point. Transition to a PSP model once you have processing history and operational maturity.
Establish your entity, file FinCEN MSB registration, and begin state MTL applications for your initial geographic scope. If you plan to serve EU merchants, begin PSD2/PSD3 authorization discussions with a national competent authority. If you plan to serve iGaming merchants, assess gaming supplier licensing requirements in your target markets.
Budget four to eight months. Come prepared with your AML program, merchant onboarding policy, chargeback management plan, and capital reserves. A legal or regulatory advisor with existing banking relationships in your target vertical can cut this timeline meaningfully.
White-label for speed to market. Proprietary for long-term control. Orchestration for multi-acquirer relationships. Do not build proprietary on your first cycle unless you have the capital and runway to support an 18-month development timeline before revenue.
Billing descriptors, digital receipts, refund flows, chargeback monitoring, and reporting. These are revenue protection. They are also the first things your sponsor bank will ask about before approving your program.
LegalBison provides specialized legal, corporate, and regulatory advisory services tailored for fintech founders and payment processors. They guide businesses through every stage of development, offering expert assistance with entity structuring, corporate setup, international licensing strategy (including MSB, MTL, PSP, EMI, and crypto/gaming permits), and direct introductions to sponsor banks and financial institutions.
Costs vary by model and jurisdiction. ISO registration is the cheapest path: USD 5,000 to USD 25,000 for initial setup. State MTLs add USD 100,000 to USD 500,000 in bonds, net worth requirements, and legal fees for multi-state coverage. A PSP model requires more capital for technology, compliance staff, and higher reserve requirements. Budget USD 250,000 to USD 1 million for a PSP launch in the US.
FinCEN MSB registration takes a few weeks. State MTLs take 6 to 18 months depending on the state and completeness of your application. EU EMI/PI authorization takes 3 to 12 months. FCA authorization in the UK takes 3 to 12 months. Gaming supplier licenses, if needed, add another 6 to 18 months.
No. Payment processors do not need a full banking license. You need a sponsor bank relationship (for acquiring) and the appropriate payment services license (MSB registration, state MTLs, EMI/PI authorization, or equivalent in your jurisdiction). A banking license is only required if you want to accept deposits and offer lending products.
Visa’s Acquirer Monitoring Program (VAMP) triggers at 1,500 combined fraud reports (TC40) and disputes (TC15) per month and a ratio of 1.5% of settled transactions. Mastercard’s Exceeding Chargeback Program triggers at 100 chargebacks and 1.5% per month. Exceeding these thresholds results in fines and potential termination. Aim to keep chargebacks below 0.75% as a buffer.
Structures like Agent of the Payee or For Benefit Of (FBO) bank accounts can let you operate under a licensed partner’s coverage. These work for early-stage validation but create dependency. Build toward your own licenses as your processing volume and geographic scope grow.
Crypto payment processing requires additional regulatory layers. In the US, converting crypto to fiat triggers MSB registration and state MTL requirements. In the EU, MiCA authorization is required for crypto-asset service providers. Travel Rule compliance applies to transfers above EUR 1,000 (EU) or USD 3,000 (US), including self-hosted wallet transfers in the EU.
LegalBison works with payment processors and fintech founders at every stage, from entity structuring and licensing strategy through sponsor bank introductions and vertical-specific compliance. If you are building a payment processing company and need guidance on where to start, contact us for a free consultation.