Building a fintech app means deciding first which regulated activities you will perform and which you will delegate to licensed partners. Most startups launch by partnering with a payment provider, a banking-as-a-service platform or a licensed broker, so that the partner holds the licence and the customer money while the startup owns the product. The first release needs identity verification, secure onboarding, encrypted data, audit trails and the partner integration. A compliant fintech MVP typically costs $100,000 to $250,000 (€85,000 to €220,000, £75,000 to £185,000) and takes 5 to 8 months.
Prices are in US dollars. Euro and pound figures in parentheses are approximate, rounded conversions. Quotes are issued in the currency of your contract.
Fintech is where founders most often discover that the product they described and the product they are allowed to build are different things. The gap is regulation, and it is manageable if it is addressed before design rather than after. This guide covers the questions to settle first, the partner model most startups use, the security baseline and a realistic budget. It is general guidance, not legal advice, and you will need a regulatory adviser in each market you enter.
What kind of fintech are you building?
Regulation follows activity. Name yours precisely:
| Activity | Examples | Typical regulatory position |
|---|---|---|
| Payments | Sending money, accepting payments, wallets | Payment or e-money licensing, or a licensed partner |
| Lending | Consumer loans, buy-now-pay-later, business credit | Consumer credit licensing, affordability rules, or a licensed lending partner |
| Investing | Trading apps, robo-advice, savings products | Investment services licensing, or a licensed broker or custodian |
| Banking | Accounts, cards, deposits | A banking licence, or banking-as-a-service on a partner's licence |
| Insurance | Policies, claims, comparison | Insurance distribution rules, or a licensed insurer partner |
| Data and tools | Budgeting, analytics, open banking apps | Lighter, but account information access is regulated in the EU and UK |
Two products that look identical to a user can sit in different regulatory categories depending on who holds the money and who makes the decision. Settle this with a regulatory adviser before discovery, because it determines the architecture.
Why do most startups launch on a partner's licence?
Obtaining a payment, e-money, credit or banking licence takes many months to years, requires capital and compliance staff, and is not something a first product should wait for. The standard route is to partner with a licensed provider: a payment processor, a banking-as-a-service platform that issues accounts and cards, a lending partner, a broker or custodian. The partner holds the licence and the client money and performs the regulated activity. You own the customer relationship, the product and the experience. Your compliance obligations are real but narrower: mostly around identity verification, data protection, marketing and treating customers fairly.
Choosing the partner is the most consequential decision in the project. Evaluate them on the markets they cover, the onboarding time for your company, their API quality, their fees at scale and what happens to your customers if they withdraw.
Which features belong in the first release?
- Onboarding with identity verification. Know-your-customer checks, often through a specialist provider, with a flow that is fast for legitimate users and robust for the rest.
- Secure authentication. Strong passwords or passkeys, multi-factor authentication, device binding, session management. Regulators expect this and users notice it.
- The core financial journey. One: send a payment, open a savings pot, apply for credit, place a trade. Done completely, including the failure cases.
- The partner integration. The connection to the licensed provider, with reconciliation so that your records and theirs agree.
- Transaction history and statements. Users must be able to see what happened, and regulators require it.
- Audit trails. Who did what, when, from where, for every sensitive action. Immutable and searchable.
- Customer support tools. Staff need to see and act on accounts, with permissions and logging.
- Consent and disclosures. Terms, fees, risk warnings and privacy notices presented and recorded properly.
Later: multiple products, cards, rewards, budgeting features, referrals, open banking connections, and additional markets.
What is the security baseline?
- Encryption of data in transit and at rest, with managed key handling.
- Card data never touching your systems. Use a provider so that PCI DSS scope stays with them.
- Least-privilege access for staff and services, with multi-factor authentication for anything administrative.
- Logging and monitoring that can detect unusual behaviour, not only errors.
- Fraud controls on onboarding and transactions, at least rules-based at launch.
- Independent penetration testing before launch and after major changes.
- An incident response plan that names people and steps.
Our post on building for regulated industries covers how these change the way a team works.
Which data rules apply?
Financial data is personal data, and often sensitive. GDPR in the EU and UK, and a growing set of state and national laws elsewhere, govern how it is collected, stored and used. Practically, this means knowing where data lives, minimising what you collect, giving users access and deletion where required, and documenting all of it. If you serve EU customers, expect questions about where the data is hosted.
What does it cost and how long does it take?
| Scope | Typical cost | Timeline |
|---|---|---|
| Data or tools product with no money movement, such as budgeting or analytics | $50,000 to $120,000 (€44,000 to €105,000, £37,000 to £90,000) | 3 to 5 months |
| One financial journey on a licensed partner, with KYC, security and audit | $100,000 to $250,000 (€85,000 to €220,000, £75,000 to £185,000) | 5 to 8 months |
| Multi-product, multi-market, with cards, lending or investing | $250,000 to $600,000 (€220,000 to €520,000, £185,000 to £445,000) | 9 to 15 months |
These exclude licensing, legal and compliance advisory costs, and partner fees, all of which you will incur. Budget for them separately and early.
What mistakes do fintech founders make?
- Designing the product before finding out what activity it is under regulation.
- Choosing a partner on API elegance alone, then discovering they do not cover the target market.
- Treating security as a phase rather than a property of every feature.
- Launching without reconciliation, then spending months finding out why the numbers differ.
- Underestimating customer support. Money problems generate urgent tickets.
How 7L builds fintech products
Banking and financial services are one of our core industries. We have built solutions that enable privacy and security compliance and the efficient management of large volumes of financial data, with high performance, cryptography and regulatory compliance designed in from the first call. We work alongside your regulatory adviser and your licensed partner so that the product, the licence and the technology line up. If you are planning a fintech product, tell us what the money does and we will help you map the route to launch.
This post is general information, not legal or regulatory advice. Financial regulation differs by country and changes often. Engage a qualified regulatory adviser in each market before building.
Frequently asked questions
Can I launch a fintech app without any licence?
You can launch a product that performs no regulated activity yourself, by using licensed partners for payments, accounts, lending or investing. You will still have obligations around identity verification, data protection and fair treatment of customers. A regulatory adviser can confirm the position for your product and market.
What is banking-as-a-service?
A licensed bank or e-money institution that provides accounts, cards and payments through an API, so that another company can offer them under its own brand. The provider holds the licence and the money. It is how most new digital banking products launch.
How long does KYC integration take?
Integrating a specialist identity verification provider typically takes two to four weeks. Designing an onboarding flow that is fast for genuine customers and robust against fraud takes longer and is worth the effort, because drop-off at onboarding is the main leak in most fintech funnels.
Do I need PCI DSS certification?
If card data never touches your systems, because a provider handles it, your obligations are limited to a self-assessment. If you store, process or transmit card data yourself, you are in full scope, which is expensive. Almost every startup should keep card data with a provider.
Is open banking relevant to my product?
In the EU and UK, open banking lets a user authorise your app to read their bank data or initiate payments through regulated interfaces. It enables budgeting tools, affordability checks and bank-to-bank payments. Using it requires either your own authorisation or a licensed aggregator partner.