We record how you arrived, to see which material leads to contact. Nothing else is stored unless you accept. How we handle data.

01 Security and enforcement

Account control agreements do not attach to electronic money institutions.

The instrument every credit committee asks for is the one the counterparty cannot sign. Substituting it is straightforward; following the substitution through the rest of the documentation is where security quietly leaks.

Published July 2026 Reading time 7 minutes For credit and legal teams

Ask any structured credit lawyer how to take control of a transaction account and the answer arrives immediately: a deposit account control agreement under Article 9 of the Uniform Commercial Code, or its English law equivalent, executed by the account bank. It is the right answer and it has been the right answer for a quarter of a century. It is also, if the account is held with an electronic money institution rather than a bank, an answer to a question nobody can act on, because the institution will not sign it.

We have now watched this play out across several drafting rounds and three separate law-firm offices. The position is well understood by the payments industry and almost unknown in the credit documentation market, which produces a predictable and expensive pattern: control agreements drafted, circulated, negotiated internally, and then abandoned when the institution declines. The purpose of this note is to shorten that loop for whoever hits it next.

Why the institution will not sign

A control agreement is a tripartite instrument in which a bank agrees to obey a third party's instructions in respect of a customer's account, typically to the exclusion of the customer's own. It assumes a deposit relationship: the customer has a claim against the bank, the bank has an account it can block, and the bank is willing to accept a standing contractual duty to a party with whom it has no primary relationship.

An electronic money institution is on a different regulatory footing. It is not deposit-taking. What it holds is electronic money, safeguarded in segregated accounts and redeemable at par, and its permissions, its safeguarding obligations and its own risk framework are built around that. Institutions have concluded, sensibly, that accepting standing third-party instruction duties across a customer base is not a product they offer. Whether the agreement is drafted under the Uniform Commercial Code or as an English law equivalent makes no difference; the objection is structural rather than jurisdictional.

The consequence for a credit team is not that the accounts cannot be secured. It is that the familiar wrapper is unavailable, and something has to be assembled in its place.

What replaces it

Three instruments, working together, get most of the way to the same practical outcome:

  • A deed of charge over each wallet, granted by the account holder in favour of the security agent. This is the security interest itself and it is ordinary English law security over a chose in action.
  • An acknowledgment letter from the institution, confirming that it has notice of the charge, that it will act on a revocation or enforcement notice within a defined period, and that it will thereafter accept instructions only from the security agent or agent.
  • A servicer power of attorney, standing and irrevocable, giving the security agent and any replacement servicer authority to give instructions in respect of the accounts without needing the servicer's further cooperation.

Between them these deliver perfection, notice, priority and an operative enforcement route. What they do not deliver automatically is the surrounding hygiene that a control agreement would have carried along with it, and that is where transactions go wrong.

Swapping the headline instrument takes one drafting round. Following it through the other nine documents takes three, and skipping it is how a collection ends up outside the charge.

Four places security leaks

1. The general security document sweeps the wallets back in

Debentures and general security agreements typically define bank accounts expansively, along these lines:

Illustrative market drafting "Bank Account" means all rights in relation to cash-deposit, current or other accounts held with any bank, financial institution or other person. Read literally, "or other person" captures wallets held with an electronic money institution, notwithstanding that a separate security mechanism is being created over the same assets elsewhere in the package.

The result is layered security over the same asset through two instruments with different perfection routes, different notice requirements and potentially different priority. That is not additional protection; it is an argument waiting to be had at the least convenient moment. The clean fix is an express carve-out for the institution-held accounts, with those accounts dealt with exclusively under the deed of charge package. Defining them separately within the debenture and providing a tailored notice form also works, but layering is worse than either.

2. The notice form does not fit the account

Schedules to English security documents carry a standard form notice to account banks with fields for sort code and account number. A wallet has neither. If the wide account definition survives, the transaction ends up with a security document that requires notice to be served in a form that cannot be completed for the accounts it purports to catch. If the carve-out is made properly the point disappears; it is worth checking that it has.

3. The perimeter does not follow the money in

This is the one that matters most, and it is the easiest to miss because it looks like a definitional tidy-up.

In a receivables programme with per-debtor payment references, collections do not arrive at the wallet. They arrive at a virtual account number, a virtual IBAN or a sub-balance linked to the wallet. If the charged accounts are identified only by their principal account numbers, there is a residual argument that a receipt sitting at a virtual account has not yet reached a charged account. The argument is probably wrong. It is also entirely avoidable, and nobody wants to be running it in front of a judge with a receiver already appointed.

Suggested formulation References to an Account include every virtual account number, virtual IBAN, sub-account, sub-balance and ledger balance linked to or issued in respect of that Account, whether existing at the date of this Deed or created afterwards. The forward-looking wording matters as much as the list: virtual accounts are issued continuously as debtors onboard, so a static schedule is out of date within a month.

4. Set-off is left to an indemnity

Institutions reserve set-off rights against balances they hold, for fees, for reversed transactions, for negative balances elsewhere in the relationship. A control agreement would ordinarily have addressed this. Where the acknowledgment letter is silent, the transaction is relying on a contractual indemnity from the borrower or servicer, which is worth exactly what that party is worth at the moment it is called on; in other words, worth least when it is needed most.

The right place to deal with it is the acknowledgment letter, by waiver or by limitation to a defined and modest set of operational amounts. Keep the indemnity as well, but as reinforcement rather than as the primary answer.

The enforcement-day timing problem

One further point, operational rather than legal, and consistently underestimated.

Acknowledgment letters often provide that the institution will act on a revocation notice subject to completing customer due diligence on the security agent or agent and their authorised users, in accordance with the institution's onboarding policies. That is a reasonable requirement in itself. The question is when it is satisfied.

If the screening runs on receipt of the enforcement notice, a delay has been engineered into the precise moment the structure exists to prevent one. The institution is being asked to onboard a new controlling party, verify named individuals and clear its own compliance checks, while the reason for the notice is unfolding. Days matter here, and days are what this produces.

The answer is unglamorous. Complete the due diligence at closing, as a condition precedent. Name the authorised individuals in the schedule, with positions and contact details. Put a covenant in the servicing agreement requiring the list to be refreshed on personnel change and confirmed annually. Then the notice does what it is supposed to do, which is to take effect within the agreed period and nothing more.

A short checklist

  • Deed of charge over each account, with the security agent as chargee.
  • Acknowledgment letter executed by the institution, with a defined response period on notice.
  • Set-off waived or narrowly limited in the acknowledgment, not left to indemnity alone.
  • Virtual accounts, virtual IBANs, sub-accounts and sub-balances expressly inside the perimeter, with forward-looking wording.
  • Institution-held accounts carved out of the general security document's account definition.
  • Standing servicer power of attorney covering instructions on the accounts.
  • Customer due diligence on the security agent and named authorised users completed as a condition precedent, refreshed on change.
  • Conditions precedent schedule updated so the corrected package flows through rather than sitting alongside the abandoned one.

Where the criticism lands

It would be convenient to end by saying the substitute package is equivalent in all respects. It is not, and pretending otherwise invites the objection to be raised by someone else on worse terms.

Electronic money is a claim against the institution for redemption at par, safeguarded rather than guaranteed, and not covered by deposit protection. In an insolvency of the institution itself, the safeguarding regime is designed to return client funds ahead of general creditors, but the mechanics are slower and less tested than a bank pledge over a deposit. A lender who prefers a conventional bank at the operating layer, and is willing to accept the loss of granularity and speed that comes with it, is making a defensible trade rather than a naive one.

What is not defensible is applying bank drafting to a non-bank counterparty and treating the resulting document as though it works. That is not conservatism; it is a control that exists only on paper, which is worse than knowing you do not have one.

Where we sit on this

Our operating layer is held with a regulated electronic money institution under a deed of charge and acknowledgment letter, with the perimeter drawn to include every virtual account, because that is how collections arrive. The architecture is deliberately provider-agnostic and can accommodate a bank at the operating layer where a lender prefers one. The instrument follows the counterparty; that is the only rule here that does not bend.