Own licence vs sponsorship: a lesson in execution
Why is a licence important in fintech?
In this article, we are going to look at what a licence is, why it's important (spoiler: it mostly comes down to speed and control) and for a budget-constrained start-up, ask the question: should you apply for a licence or rent one?
A little further down I've listed the common types available in the UK and Europe, but before we go into that, let's talk a bit about licences themselves.
In most walks of life, where there is a material risk of harm from the provision or consumption of a product or service, it begets a government to enforce some kind of control on the circulation of said thing. (unless you are the BBC in the UK, in which case it's just a giant racket).
The end state for such a process is typically a dedicated organisation that acts as a gatekeeper of the said goods and services. The organisation then issues a framework and control set that each potential operator must abide by and, in doing so, are granted a licence to perform either all or a subset of the activities permitted under that licence.
In financial services, there are various types of regulators and even more various types of licences. For the purposes of this article, I'm going to assume you aren't a Palmer Luckey, a Nick Ogden, or a David Jarvis and, therefore, you aren't starting a full-fat Bank. There are two reasons for this assumption.
One is that there is a limited pool of banks in the world and an extremely finite number of founders who are capable of starting a bank. These individuals are typically hyper-capable and don't need this kind of material to aid them on their journey. There are also just not that many of them, so the impact of writing a guide would have little real-world value and the aim is to help as many people as possible.
The second reason is that while I work with banks as customers, partners, and suppliers, I have never applied for a licence of that type; therefore, backseat driver guidance isn't very useful. Where I have first-hand experience, I want to share it. Where I don't, I won't.
What the team at IF have done is worked for, built, and scaled licensed fintechs, so we have the battle scars and I'm more than comfortable giving guidance on all things licence in the Fintech EMI/API (non-bank) space.
An EMI is one of the most common types of licence one can acquire in the UK/EU these days. It allows for the holding of money (issuing of e-money as they term it) but not the payment of interest. In a nutshell it means you have to hold client balances 1:1 and as a result have no room for creative endeavours that would generate interest. If a Full Banking licence is "full-fat" you can consider this a Diet Banking Account - with the crucial caveat that you can't use the word 'Bank'.
Types and their permissions
*Whilst in theory Payment Institutions (API or SPI) are not allowed to issue wallets or store client money, the practical application of the permitted activities means these aren't really enforceable. The FCA in its handbook dictates you can't issue E-money - but "you must actively notify the customer of the overpayment via multiple channels (email, dashboard alert, phone)." In practice at scale, customers often leave minor amounts of funds on account through negligence, laziness or convenience. The key is to encourage this to happen as little as possible. The FCA requests you refund this, but in reality this leads to poor customer experience, additional unnecessary fees and becomes impractical at scale to enforce.
The reality today is that the Authorised Payment Institution (API) is a vestige of a previous time and that nearly all fintechs launching today will be aiming to gain E-money Permissions or E-money Sponsorship. It effectively allows you to retain customer deposits which gives you huge flexibility when it comes to business model, customer experience and retention. Holding funds allows you to become part of your customers' habit rather than a temporary administrative solution.
So what does a licence actually get you?
A licence ultimately gives you (greater) agency over your business. It gives you (a greater) amount of autonomy over who you serve. It gives you (more) control over your business model and pricing decisions. If you have a licence, you can take (greater) control over how you market your product. You have few(er) approvals to get decisions made. You don't have to ask permission of the licence holder for minor or material changes to the business.
A licence reframes the debate from one of 'can' to one of 'should' (also as I wrote those words I felt distinctly like an LLM—I'm not, I promise).
What I mean by this is when you are using somebody else's licence, you are in a perpetual state of waiting for permission.
"Can I market my product as bank…like?"
"Can I launch without having a compliance team in place?"
"Can I charge 7% FX rates for my vulnerable customers?"
"Can I not screen these payments that look distinctly suspicious?"
"Can I onboard this 115-year-old individual for my memecoin?"
"Can I issue a glass mirror physical card?"
"Can I [INSERT YOUR OWN AWFUL IDEA]?"
When you have a licence, the question doesn't disappear; it merely becomes one of 'should.'
"Should I market my product as bank…like?"
"Should I launch without having a compliance team in place?"
"Should I charge 7% FX rates for my vulnerable customers?"
"Should I not screen these payments that look distinctly suspicious?"
"Should I onboard this 115-year-old individual for my memecoin?"
"Should I issue a glass mirror physical card?"
"Should I [INSERT YOUR OWN AWFUL IDEA]?"
In both framings, you hopefully arrived at the same answer—NO. Ideally, your certainty on the answer progressed from "obviously" to "what kind of idiot would…"—you get the idea.
The point is just because you can, doesn't mean you should. Your problems don't disappear with a licence. They just become… exclusive. Exclusively yours. Consider some of the examples above:
"Can I onboard this 115-year-old individual for my memecoin?"—If you don't own your licence, the answer from the Sponsor will be a categorical 'NO'.
Now let's reset and replay the scenarios where you do have your own licence.
"Should I onboard this 115-year-old individual for my memecoin?"—Well, let's consider the answer. It's a useful exercise. Here goes…
It's currently 2026 and there are precisely (checks AI) 4 people of this age in the entire world. This brings up consideration number 1: Solicitation. Is your product so WILDLY successful that people from every demographic are flocking to use you? If so, that's 1 point in your favour. If, however, you are a new start-up and scrapping for every single user, the fact that you have acquired interest in a prospective customer that occupies possibly the RAREST cohort known to man would strongly suggest you are targeting this user type. Now, SOME might say that to acquire a user from such a rare breed, one would have to be very deliberately and highly effectively targeting this cohort. Again, in and of itself, no bad thing; that just means you are excellent at marketing. A cynic might point out that this is an unusual thing to do because A: people in this age category often struggle to beat their heart and breathe. Their children often struggle with all sorts of age-related diseases and are mostly retired (if not dead already). Hell, even their grandchildren are probably all retired and have enough IT problems just trying to find their downloads folder that being able to sign up for and trade memecoins may be a little bit out of reach.
That is to say, why on earth would you be soliciting business from such an unusual and (dare I say it) vulnerable customer set? Now, the regulatory rules in the UK and EU very clearly call out a duty of care to all customers, but especially those deemed vulnerable. Vulnerable customers are broadly defined, but a key "driver", according to one regulator, is mental capacity and health. A 115-year-old, by any standard, is likely to be vulnerable due to their health (potential cognitive impairment) and, therefore, just the fact that you would try to sell them a memecoin (prone to massive uncertainty) would seem to violate this duty of care…
Now why am I (at painstaking length) going into such an example? The point I am trying to make is that while having a licence means you own your own destiny, it shouldn't materially change most of the fundamental aspects of your business. Most founders will come to the same rational conclusions on where the boundaries of what is ethical/fair/justifiable lie when running a heavily regulated service. Yes, there is always a risk appetite question, and younger fintechs with 0 revenue will typically lean into risk vs. grey-haired execs who have billions of dollars of revenue to steward. But in general, most fintechs are aligned on what "duty" looks like, and it's merely at the margins things get murky.
The point I am trying to drive home is that if you think getting a licence will allow you to do whatever you want and become the master of your own destiny, that's simply not true. You will still be referencing your decision-making against the same (or very similar) source material that your sponsor would have been doing. You still have a duty of customer care, a duty of reporting suspicious activity, a duty of preventing financial crime, and a duty of care for your own financial operations.
BUT…
What having your own licence does provide…
Honestly, the biggest thing is speed and control. I think in the long term, a good proxy for business success is its rate of innovation. Businesses that stop innovating are eventually eaten up by those that do. Businesses that don't respond to change often fall into obscurity or, worse, the history books. Rate of change is crucial in business. And having your own licence allows you to move, and decide, at your own pace. If that pace is slow, you'll die. But at least it will have been your own fault.
Depending on a sponsor for a licence can be slow and, if not managed carefully, can mean you lose control.
Why? Let's say you are their biggest customer. Even in that case, they have their own business to run. And you will always be second fiddle to their own existential threats. In some cases, you might even be the existential threat. Secondly, let's assume you are not their biggest customer. That means you will likely be third fiddle to the needs of that customer. Let's imagine an 'all-else-being-equal' example. You are one of 20 customers of equalling model and economic value to the sponsor. That's still 20 customers who the sponsor has to keep tabs on. 20 customers to respond to. To enter multi-month projects with. To respond to, to admonish, to investigate, to audit. And on and on.
Founder Reality Check #1: The Approval Tax
Consider this simple example.
…You are growing like crazy and your CMO and CPO have done market analysis and customer research. They tell you that if you offer a new Premium subscription to your product, there is an 87% chance that you will convert 10% of your established user base to it and it will drive 100K more MRR. In fact, it's the most demanded thing on your community Slack channel.
It makes total sense, there is no additional fraud or ML risk ….llllleeeets GOOOO!
…And then you remember in your contract with your Sponsor, you explicitly agreed that as they are the regulated entity ultimately responsible for the duty towards and care of the customer (because in the event that your business fails, it's their problem), that any material changes to the product, ESPECIALLY any that have an impact on fees the customer faces, must first be reviewed and approved in writing by the Sponsor's Approval Committee. And by the way, the Approval Committee meets once a month on the 68th Thursday of each calendar quarter and the submission must be in Comic Sans with an SLA response time of 3 months and if you make a grammar error in the initial request it will be auto-rejected by their spam filter... and well you get the idea.
And leeeeetttssssssssss nooooo.
So, you ask the question to your Sponsor, and you patiently wait. Days pass and no response. Your agreed SLAs approach, occur, and sail past with nary a "we're on it." After all that, you finally get a vacuous response (resetting the SLA) that asks some banal questions about how and why you want to do it and by when.
Now lather, rinse, and repeat the above scenario. Repeat your team's product meetings. Your GTM strategy debates. Your marketing team's Friday ideation hub. Your designer's late-night brand guideline sessions. Repeat it across your board meetings and your Investor Q&As. Hell, even your hiring decisions will be impacted by this. You wanted to hire a growth hacker? Too bad; the Sponsor felt your MLRO didn't have enough experience. Go spend another 100K on a 15-year seasoned exec.
The decision-making apparatus of your business will remain in the perpetual shadow of your sponsor. They are granting you access to their most prized asset. And they will be watching closely at all times to make sure you don't jeopardise it. As a founder, this will be doubly painful. Not only will half-listening investors roll their eyes when you reject their ideas outright 'because sponsor says no,' but you will have your staff continually complain that reasonable ideas just aren't worth the friction it will generate across teams to actually make it happen. It basically requires the non-technical equivalent of a DevOps deployment. A team of people to roll your idea into production in a carefully managed and always permissioned manner, usually to the chagrin of everyone and to the satisfaction of none.
Let me give you some more tangible examples. Yes, it's tactical, but ultimately the tactics one adopts inform the strategy one adheres to. Sure, the discerning founder will roll their eyes and say "well that's just a paper cut - easy to deal with". And they'd be right, until they aren't. Paper cuts hurt like hell, and are hugely distracting when you are trying to go about your day. And enough of them hurt the mission.
Founder Reality Check #2: The Velocity Tax
Something as simple as trying to change a velocity limit.
For those of you who don't know what a Velocity Limit is: ChatGPT's distillation of the Oxford English Dictionary says that:
"A velocity limit is a cap on how many times something can happen within a set period.
In fintech, examples include:
- Maximum 5 card transactions per minute
- Maximum £2,000 transferred per day
- Maximum 3 failed login attempts per hour
- Maximum 10 cash withdrawals per week
It is mainly used to reduce fraud, money laundering and operational risk. Unlike a simple value limit, a velocity limit looks at the frequency or accumulated activity over time."
Now usually a Sponsor Bank will do one of two things. They will go full Sauron and build one set of rules to rule them all. (Good for Sponsor but problematic if you don't fall into the bullseye of the Sponsor's target market.)
A more reasonable Sponsor will engage with each fintech they work with and set appropriate rules for the demographic you target.
The problem is you can only guess at what works for your customer set. And these rules need to be in place at launch. Imagine the scenario where you are onboarding customers like crazy and you are getting traction, beginning to grow and scale, when your customer service team starts smelling of smoke as the phones slowly begin lighting on angry customer fire. (hell hath no fury like a consumer whose card gets declined for no reason).
You handle your investigation; your customers are who they say they are, it was them performing that transaction, they are not being coerced, they have validated the service is legit and on and on. Why are all these transactions failing? You check the technical integration; APIs all green lights. Card Processor working fine. And you realise it's your velocity limits. It just so happens that the expected pattern of your typical consumer behaviour doesn't quite match your fraud signals. Specifically your velocity limits.
Turns out for some reason, a bougie Instafamous influencer was showing off their cool new card and a boatload of St Tropez Trust fund kids all got your card and are spending big. And they are LIVID that they were made to look the fool when their cards got declined at Gucci. Why? Because you hadn't anticipated success in that market and your velocity limits (aimed to protect you and your customer) are out of whack with your consumers' spending patterns and now all their payments are failing. The Instafamous influencer is getting doxxed for falsely advertising something and your brand is smoking (no, no, the bad kind).
Now that you've realised the issue, you rush to your operations teams to adjust the velocity limits and… they tell you "umm ackssssually, we can't change this without the permission of the sponsor".
It's at moments like these when above all else, one needs agency and control (in the autonomous sense…).
Agency to respond and act quickly, in a situation that can rapidly escalate if it is allowed to continue uninterrupted. Once the issue has been identified, the shortest path to solving the issue is almost always the correct path. However, where you depend on the licence of a third party, changes like these simply must be consulted on. And as a result, the sponsor becomes the slowest moving part in a chain. And issues in supply chains only resolve as fast as their slowest moving part.
Conclusion
Owning a licence in the early years of running a financial service is less about having total ownership of your risk appetite and customers. It's much more about being able to move at your own pace. Small fintechs are able to hyperfocus on a relatively small set of users and rapidly iterate a product that those users love. And from there, they can scale across that target segment. A licence is not crucial to do the above. But having absolute clarity from your Sponsor Bank on what they will or won't allow is a must. Better yet, delivering scenario examples like the ones I have listed and getting clear answers on how much autonomy a Sponsor would give you to react could mean the difference between scaling and failing.
Remember, sponsors don't really generate any wins unless they help to build successful fintechs. But they will always have one eye on the mess you could leave when the music stops.
A licence is important for self-determination, speed, and control, in the long run. But in the short run, if you can engage with a Sponsor and ensure they won't hold you back in your time of need, it's often the right way to go.
To do this, I can't recommend enough scenario rehearsals. Come up with 10/15 things your team may or may not want to trial as your team scales.
Everything from marketing, to product to compliance to ops. Imagine happy and non-happy path deviations from your standard operating procedures. And tell your Sponsor Bank: if scenario A happens we would like preapproval to change pricing to X. If scenario B happens, we would like preapproval to change our velocity limits to Z. And on and on. This can be the difference between success and failure.
And the reason rehearsals matter so much is that nobody negotiates well at 2am with a support queue on fire. A scenario you have already walked through is a decision your Sponsor has effectively already made. A scenario you haven't is a three-month SLA and a roadmap on hold.
Rehearsals move the argument from 'can we?' to 'we already agreed we could', and they do it while the stakes are still hypothetical and everyone is still being reasonable. They also smoke out the answers you actually needed before you signed - the polite 'we'd have to look at that' that really means no. Far better to learn that now than in the middle of your best growth month.
And as a bonus, the mere fact that you are even thinking about this will likely get the Sponsor to give you more of their attention.
A licence is a lot. But it's not everything! It just means the gatekeeper is finally you — and unlike the BBC, nobody hands you the racket for free.