What We Build for a Fintech Company
A fintech company needs five things that fit together: a regulated operating entity in the licensing jurisdiction, the initial capital the regime requires, a payment institution or electronic-money institution authorisation, banking for both client funds and treasury, and a live compliance stack covering AML/CFT, DORA and PSD2 reporting. We deliver all five, and we deal with the regulator directly to do it.
The licence is the gate. Inside the EU these are the PI authorisation under PSD2 and the EMI authorisation under EMD2; in the UK, authorised PI and authorised EMI under the FCA regime; in the UAE, one of three regulators (the CBUAE onshore, the ADGM FSRA, or the DIFC DFSA). We identify the right route before a single fee is paid, set the capital structure to meet the regulator’s minimum and the ongoing own-funds requirement, and build the compliance function before launch so it survives the first supervisory contact, not just the application.
What We Deliver
| Component | What we do | Typical Timeline | More detail |
|---|---|---|---|
| Company formation | Incorporate the regulated operating entity in the licensing jurisdiction | 1 to 4 weeks | Company formation |
| Licensing (PI or EMI) | Draft and file the authorisation, and deal with the regulator through to grant | 4 to 12 weeks drafting; 3 to 18 months regulator review depending on jurisdiction | EMI & payment licensing |
| Safeguarding banking | Place client funds with an authorised credit institution under PSD2 Article 10 / EMD2 Article 7 | 4 to 10 weeks once compliance documentation is complete | Banking |
| Operational banking | Arrange treasury, payroll, FX and vendor-payment accounts for the licensed entity | 2 to 6 weeks | Multi-currency accounts |
| Card scheme or BIN access | Set up card issuing (EMI) or acquiring, via direct scheme membership or a principal-issuer programme | 8 to 24 weeks | (reference only) |
| Ongoing compliance | Build the AML/CFT programme, MLRO function, safeguarding audit, DORA ICT controls and PSD2 reporting | Permanent operating function | (cross-reference within page) |
Choosing the Right Jurisdiction
We pick the jurisdiction with you before anything else, because it sets the regulatory framework, the capital requirement, the market access, the corporate tax treatment and the realistic timeline. We deliver formation and licensing principally across the EU, the UK and the UAE. Inside the EU, Estonia and Cyprus offer PSD2/EMD2 authorisation with full EEA passporting at materially lower cost and timeline than the larger Member States, which is why we route most pan-EU plays there. The UK FCA runs a comparable regime but holds no EU passport post-Brexit. The UAE has three regulators with three distinct frameworks. One thing to be clear about: e-money issuance requires authorisation in a jurisdiction with an EMI-equivalent framework, so it cannot route offshore the way a crypto VASP can. Canada and Australia accommodate remittance-led payment services with no prudential capital floor, but do not issue an e-money licence in the European sense.
Fintech Licensing Jurisdictions Compared
| Jurisdiction | Regulator | Licence Types | Initial Capital | EU Passporting | Corporate Tax |
|---|---|---|---|---|---|
| Estonia | Finantsinspektsioon (FI) | Authorised PI; PI by exception; Authorised EMI | €20k / €50k / €125k (PI by service); €350k (EMI) | Yes (PSD2 Art. 28) | 22/78 on distributions (effective 22%) |
| Cyprus | Central Bank of Cyprus (CBC) | Authorised PI; Authorised EMI; AISP-only registration | €20k / €50k / €125k (PI); €350k (EMI) | Yes (PSD2 Art. 28) | 15% CIT (from 1 Jan 2026); 2.65% GHS on dividends to residents |
| United Kingdom | Financial Conduct Authority (FCA) | Authorised PI; Small PI; Authorised EMI; Small EMI; Registered AISP | £350k-equiv.≈ $471K (AEMI); £20k≈ $27K / £50k≈ $67K / £125k-equiv.≈ $168K (API by service); lower for small categories | No (post-Brexit) | 25% main rate |
| United Arab Emirates | CBUAE (onshore RPSCS + SVF); ADGM FSRA Cat 3C; DIFC DFSA Cat 3C/3D/4 | RPSCS; SVF; ADGM Money Services; DIFC Providing Money Services; DIFC Stored Value Issuer | CBUAE: risk-based; ADGM 3C: USD 250k; DIFC 3D: USD 200k; DIFC 3C SVI: USD 500k; DIFC 4: USD 10k (advisory only) | No (third country to EU) | 9% federal CT above AED 375k≈ $102K; 0% QFZP with substance |
We recommend Estonia when the priority is EU passporting at the credible floor on cost and timeline. Licensing capital sits at the PSD2/EMD2 minimum, the regulator runs a fast review cycle, and the distribution-based corporate tax leaves retained earnings untaxed at the entity level. See our Estonia licensing page for the operational detail.
We recommend Cyprus when the priority is a Mediterranean base with English-speaking professional infrastructure and a regulator that has actively built EMI capacity. Throughput is healthy rather than closed. The headline corporate tax rate understates effective economics once the GHS levy is in, and we model that for you.
We recommend the United Kingdom when the target market is sterling-denominated and the value of an FCA-grade institutional brand outweighs the loss of EU passporting. The Small EMI and Small PI categories give early-stage operators below the €3m monthly average payments threshold a low-friction start. The trade-off is real: a UK EMI cannot passport into the EU.
We recommend the UAE when the target market is the MENA region or an institutional base served from ADGM and DIFC. The three regulators are not interchangeable, and we identify the right one and file accordingly. The federal corporate tax is offset by 0 percent free-zone treatment for Qualifying Free Zone Persons that meet the substance tests.
For purely remittance-led models without e-money issuance, Canada and Australia operate AML-anchored registration regimes with no prudential capital floor. These sit outside the routes we deliver; if your model points there, tell us and we will be candid about whether we are the right firm for it.
We Form the Company
Formation is the first thing we do for you, because capital, the licence application and banking all need a registered entity. The most common mistake we see is a founder who has already incorporated in a tax-optimised jurisdiction that does not host the chosen licensing regulator, then faces restructuring once the file opens. We do not let that happen.
We use the right vehicle for each jurisdiction (set out below) and handle the share-capital timing, which differs: Estonia and Cyprus accept paid-in contributions before the licence file progresses, while the UAE typically requires the licensing capital paid up before the application is submitted. Director and management substance matters more for fintech than for most regulated activities, because the regulator assesses the firm’s risk-management depth as part of the review. EU regulators apply fit-and-proper tests to directors and substantial shareholders, and substance tests to the management function: a registered office that is in fact occupied, executive management that is in fact resident, an MLRO who is in fact accountable in the jurisdiction. We build the structure to meet those tests rather than to fail them later.
Formation Snapshot by Jurisdiction
| Jurisdiction | Entity Type | Formation Timeline | Capital at Formation |
|---|---|---|---|
| Estonia | Osaühing (OÜ) | 1 to 3 weeks (faster with e-Residency) | Nominal at formation; licence capital paid in before file progresses |
| Cyprus | Private Limited Company | 2 to 4 weeks | Nominal at formation; licence capital paid in pre-application |
| United Kingdom | Private Limited Company | 1 to 2 weeks | Nominal at formation; licence capital paid in pre-submission |
| United Arab Emirates | ADGM SPC / DIFC Co Ltd / Free-Zone Co / Mainland LLC | 4 to 10 weeks (free-zone), longer for mainland | Capital paid up before licence grant; typically pre-application |
e-Residency in Estonia is useful for non-resident founders managing the entity remotely, but it does not substitute for the substantive presence the regulator expects from the management function during the licence file, and we tell you so plainly. We favour a simple structure, the operating entity in the licensing jurisdiction with one layer of holding above and real substance in both places, because it survives the fit-and-proper review rather than triggering an indirect-parent substance assessment mid-application.
We File the Licence
This is the core of what we do. A fintech operating in the EU needs either a payment institution (PI) authorisation under PSD2 or an electronic-money institution (EMI) authorisation under EMD2. We draft the application, assemble the file, and deal with the regulator directly through to grant. Outside the EU, the route depends on the jurisdiction’s framework, and we map it for you before you commit.
EMI or PI follows the product. A PI may provide payment services but cannot issue electronic money; an EMI may issue e-money and provide payment services. So an e-wallet, prepaid card, tokenised balance or euro stablecoin that holds customer balances needs an EMI; a money-remittance app, payment-initiation service or card-acquiring business that does not hold balances is a PI. EMI initial capital is €350,000; PI capital runs €20,000 to €125,000 by service scope, with an ongoing own-funds requirement on top. We size this with you, then file the right category the first time. PSD3, once in force, collapses the two into a single payment-institution framework with e-money issuance as an authorised sub-service.
Passporting and the agent model. An EU-authorised PI or EMI passports across the EEA by notification to the home regulator. Before its own licence is granted, an early-stage fintech can also operate as an agent of an authorised principal (registration typically takes two to three months), the standard time-to-market shortcut. Agents cannot themselves issue e-money: only the principal EMI may. We set up whichever route fits your launch.
Euro stablecoins. Under MiCA, only credit institutions and EMIs may issue e-money tokens, which are treated as electronic money. A founder building a euro stablecoin therefore needs an EMI licence as a prerequisite, plus MiCA Title IV authorisation, plus a PSD2 capital overlay if any crypto-asset service activity sits inside the operating entity. We structure the entity so those requirements stack cleanly rather than colliding.
Beyond the EU. In the United Kingdom, the FCA regime mirrors PSD2 in substance, with the practical difference that there is no EU passport and the FCA operates Small EMI and Small PI categories for firms below the €3m monthly average payments threshold. In the United Arab Emirates, three regulators apply and we identify the right one: the CBUAE for onshore retail payments and stored-value facilities, the ADGM FSRA for Money Services Business permissions, and the DIFC DFSA for Providing Money Services and Stored Value Issuer permissions.
For the full EMI and payment-institution service, see our EMI and payment licensing page; for the UK route under Brexit conditions, see our licensing overview.
Banking, as Part of the Build
Banking is the most underestimated component of a fintech launch, and we treat it as one of our core services, delivered alongside the formation and licensing work. A licensed fintech needs two arrangements: a safeguarding arrangement for client funds, which is the regulator’s gate, and an operational account for treasury, payroll, FX and vendor payments, which is the firm’s runway. We arrange both alongside the licence.
Safeguarding is the binding constraint. The credit institution issues a safeguarding acknowledgement letter confirming trust status, off-balance-sheet treatment, no set-off and exemption from the general lien, and the regulator wants the executed letter, not a draft, so we secure it early. A generic template adapted from another fintech will not survive the first information request. Because we secure that letter before the file goes in, the regulator’s safeguarding question is answered when the file is read, not after, which in our experience shortens the path to authorisation by four to ten weeks. We know which institutions hold credible appetite for fintech profiles and approach them directly on your behalf rather than handing you a list. We never name a bank in public and we never offload this work to an unverified third party.
We Build the Compliance Stack
Compliance is a permanent operating function, not a one-time licensing event, and we set it up so it works from day one rather than scrambling after the first supervisory contact. For an EU-authorised EMI or PI the perimeter runs across AML/CFT, PSD2 conduct and reporting, safeguarding audit, complaints handling, passporting notifications and DORA. We build each into the application file and hand you a function that runs.
AML/CFT. EU PIs and EMIs are obliged entities, with the new AML Regulation applying in full from 10 July 2027 and AMLA already operational in Frankfurt. We stand up the MLRO function as a permanent senior-management appointment and write the AML/CFT manual as a living document the regulator can request at any time.
Operational resilience. DORA has applied to PIs, EMIs and CASPs since 17 January 2025. We build the ICT risk-management controls, the incident-reporting process and the Register of Information on ICT third-party arrangements that it requires, so the firm is resilient from launch rather than retrofitting later.
Reporting, safeguarding audit and conduct. We set up the PSD2 fraud and incident reporting cycles, the annual independent safeguarding audit required across all EU and UK regimes, the complaints-handling perimeter, and the passporting and material-change notifications to the home regulator. Capital adequacy is reviewed annually against the higher of the initial capital and the own-funds requirement, and we keep the firm on the right side of it.
Realistic Timeline
The realistic end-to-end timeline from formation to operational launch is six to eighteen months. The variance comes from the jurisdiction, the completeness of the file at first submission, and whether safeguarding is sequenced alongside licensing or after it. We sequence it alongside, which is the single biggest lever on speed. We do not publish fees here, because every fintech launch is scoped differently; we give you a firm quote once we understand your model.
End-to-End Timeline by Phase
| Phase | Timeline | What we do |
|---|---|---|
| Company formation | 1 to 4 weeks | Incorporate the operating entity in the licensing jurisdiction |
| Banking | 3 to 5 days to identify the route; placement 4 to 10 weeks downstream | Approach credible institutions directly and secure the safeguarding leg early, alongside capital deposit and file drafting |
| Licensing application drafting and filing | 4 to 12 weeks drafting; 3 to 18 months regulator review | Draft the file and deal with the regulator through to grant; EU/UK EMI authorisation at the longer end |
| Pre-launch readiness | 2 to 6 weeks | Governance sign-off, MLRO induction, safeguarding-letter execution, DORA register set-up, external-audit engagement |
| Total to operational launch | 6 to 18 months realistic | One accountable firm across every phase; the dependency sequence drives the variance more than the regulator’s pace |
What we do to compress it: pre-qualify safeguarding before capital is locked, pre-draft the compliance documentation, present a clean fit-and-proper file, and choose a regulator with a track record of moving files. What expands it, and what we steer you away from: safeguarding left until after the application, a late MLRO appointment, a parent-company structure the regulator assesses for indirect substance, and an over-engineered scope that triggers several service-line authorisations at once. Timeline guidance is current as of May 2026.
Frequently Asked Questions
Do I need an EMI licence or a PI licence?
You need an EMI licence if the business issues electronic money: e-wallets, prepaid cards, tokenised balances and euro stablecoin issuance all require one. A PI licence is sufficient for money remittance, FX-as-a-service, card acquiring, payment initiation and B2B payment-rails plays that do not hold customer e-money balances. Once PSD3 is in force, the standalone EMI category disappears and e-money issuance becomes an authorised sub-service of a payment institution rather than a separate licence type.
Can I use an agent model to launch faster?
Yes. Before your own licence is granted you can operate as an agent of an EU-authorised principal, with agent registration typically taking two to three months from filing. The limit is that agents cannot themselves issue e-money: only the principal EMI may. It is the standard time-to-market shortcut, and we set it up where it fits your launch.
Can a UK EMI passport into the EU?
No. Post-Brexit, UK EMIs and PIs have no PSD2 or EMD2 passport, and the temporary permissions regime has closed. A UK fintech serving EU customers has two realistic routes: authorise an EU subsidiary in Estonia, Cyprus or another Member State and passport from there, or operate as an agent of an EU-authorised principal. We deliver either.
How much does it cost to launch a fintech company?
The cost you cannot avoid is regulatory capital, set by the regime: €350,000 for an EU EMI, €20,000 to €125,000 for a PI by service scope, and the published thresholds for the UAE categories. On top of that you need operating runway to reach break-even. Our own fee depends on the jurisdiction, the licence type and the scope of the build, so we do not quote a number here. Tell us your model and we will give you a firm quote. Book a free consultation.
How long does an EMI or PI authorisation take?
The procedural minimum is three months from the date the regulator confirms the application complete, with a maximum of twelve. Real-world timelines run longer because the completeness clock stops and starts across information-request cycles: realistically 6 to 9 months in Estonia, 9 to 18 in Cyprus, 6 to 18 with the UK FCA, and 6 to 14 in the UAE. The variable that most determines the timeline is the number of information-request cycles, which is exactly what a clean, complete first filing reduces.
Launch Your Fintech With One Accountable Firm
We form, licence and bank fintech companies across the European Union, the United Kingdom and the UAE. We file the work, deal with the regulator directly and stand behind the outcome. Tell us your model and we will scope it with you.
Banking & Payments
A company and a licence still need a bank account
Banking is one of our three core services. We help high-risk and regulated businesses open the bank and payment accounts that others refuse: we work directly with EU EMIs, payment institutions and crypto-aware banks, confirm appetite before you apply, and make the introduction. Take it with your company and licence, or on its own.
Related Services
- EMI & Payment Institution Licensing: we obtain PSD2 PI and EMD2 EMI authorisation across the EU, UK and adjacent markets
- Banking for Fintech & High-Risk: safeguarding and operational banking arranged directly alongside your licence
- Multi-Currency Accounts & IBANs: dedicated and virtual IBANs, foreign exchange and multi-currency business accounts
- Estonia Crypto & Fintech Licensing: our Finantsinspektsioon route under MiCA and PSD2/EMD2
- European Company Formation: EU and EEA entity formation including PSD2/EMD2 passporting routes