Industry
Digital, software and AI for fintech and payments
Startup growth expectations inside a supervised institution, where onboarding conversion and financial crime obligations pull in opposite directions.
Fintech carries a tension that ordinary software companies do not: everything that improves conversion at onboarding tends to weaken the financial crime controls the licence depends on, and everything that strengthens those controls costs conversion. Managing that trade-off deliberately is most of the operational work.
The second fact is supervisory. A licensed institution outsourcing to a supplier brings that supplier inside the perimeter — audit rights, exit plans, documented processing locations — and a supplier who has not encountered that will slow the compliance function down badly.
Why this sector is moving now
Licensing has concentrated in a few jurisdictions, notably Lithuania for electronic money and payment institutions, which means a large population of supervised firms with growth expectations set by venture investors rather than by banks.
Onboarding is where most of the measurable value sits. Drop-off during identity verification and source-of-funds checks is high, and the difference between a well-designed flow and a poor one is a large share of acquisition spend either converting or not.
Reporting obligations are frequent and format-driven, and firms that treat them as periodic manual exercises carry both a cost and an error risk that automation removes cleanly.
The pressures behind it
- Onboarding conversion against controls
- Every friction reduction tests the financial crime controls the licence depends on.
- Supervisory outsourcing rules
- Obligations that reach the supplier, including audit rights and exit planning.
- Financial promotion restrictions
- Claims about products, returns and protection constrained and requiring approval records.
- Reporting frequency
- Regular submissions in changing formats assembled from systems that do not connect.
- Screening false positives
- Sanctions and PEP screening generating manual review volume that scales with growth.
- Investor-grade metrics
- Numbers that must reconcile with ledgers when examined properly.
Where the work usually starts
Almost always onboarding: measuring where applicants actually drop out, then reducing friction without weakening the controls. It is bounded, it is measurable, and it directly affects the return on every acquisition euro already being spent.
Screening triage follows, since false positive volume grows with the customer base and is the operational cost most likely to outrun headcount. Reporting automation after that.
Marketing and brand for fintech and payments companies
- Brand Strategy & Development
- Fintech positioning defaults to being faster and simpler than incumbents, which every entrant claims. Durable positioning is usually a customer segment underserved for a structural reason, and articulating that reason is what makes the claim credible.
- Brand Management
- Regulated disclosures, protection statements and risk warnings appear across product surfaces and marketing, and they are frequently inconsistent because different teams produced them. Consistency here is a compliance matter as much as a design one.
- Social Media Strategy
- LinkedIn for B2B fintech and a genuinely constrained environment for consumer products, where a post about a financial product is a promotion. Founder-led content works and needs the same approval discipline as anything else.
- Social Media Management
- The risk is an unapproved claim in a reply or a comment about returns or protection. Approval workflow and retention of what was published are regulatory requirements rather than good practice.
- Content Creation & Creative Production
- Educational content sits more comfortably inside promotion rules than product claims do, and it happens to be what people search. Explaining a mechanism honestly, including limitations, is both safer and more effective.
- Digital Marketing
- Acquisition cost has to be measured against onboarded and active customers rather than signups, because the gap between the two is where fintech marketing budgets disappear. Signup-level reporting systematically overstates performance.
- Paid Advertising
- Platforms restrict financial advertising and require verification, and the landing page falls under the same regulatory rules as the ad. Two sets of rules apply — the platform's and the regulator's — and satisfying one is not satisfying the other.
- Search Engine Optimisation
- Explanatory content on mechanisms, fees and comparisons is the workable ground. Product pages compete against comparison sites with more authority, and claim restrictions limit what those pages can say anyway.
- Email, SMS & WhatsApp Marketing
- Onboarding completion sequences are the highest-value programme, recovering applicants who abandoned during verification. Regulated customer communications sit alongside and have their own timing and retention rules.
- Lead Generation & Prospecting
- Viable for B2B fintech selling to businesses. Not appropriate for consumer financial products, where unsolicited approach is restricted and reputationally damaging.
IT, software and AI for fintech and payments companies
- Website Design & Development
- The onboarding flow is the product for most fintechs, and abandonment concentrates at the identity and document upload steps. Saving progress, explaining why information is needed and handling mobile document capture properly move conversion more than design does.
- CRM & Sales Systems
- Customer records carry regulatory significance — risk rating, screening status, review dates — alongside commercial value. Retention and access controls shape configuration before pipeline design does.
- Business Process Automation
- Onboarding document collection, periodic review scheduling, screening refresh, and reporting assembly. Periodic review in particular is a recurring obligation that scales with the customer base and is frequently manual.
- AI Automation Systems
- Document extraction from identity and source-of-funds evidence, and triage of screening alerts to reduce manual review volume. Anything that makes or materially influences an onboarding decision falls under automated decision-making rules and needs specialist regulatory input.
- AI Knowledge Bases & RAG
- Regulatory handbooks, internal policy, product terms and past decisions, retrievable with citations and permissions enforced at retrieval. Compliance teams answer the same questions repeatedly from documents that are hard to search.
- AI Voice & Customer Communication
- Identity verification prompts and status enquiries are bounded uses. Calls in this sector frequently carry recording and retention obligations that shape the architecture before the use case is chosen.
- Custom Software & Platforms
- Justified for onboarding orchestration, back-office tooling and reporting layers. Anything touching the ledger, settlement or safeguarding is specialist territory and we would say so rather than take it.
- Data Engineering & BI
- Metrics that reconcile with the ledger under examination — active customers, transaction volume, unit economics, cohort retention. Definitions and lineage matter because an investor or a supervisor will ask how a number was produced.
- Cloud, DevOps & Infrastructure
- Supervisory outsourcing expectations govern processing location, audit rights and exit planning, and they are scoping questions rather than contract clauses. Logging and change management need to satisfy an audit rather than a preference.
- Systems Integration
- Core ledger to CRM, screening providers to onboarding, reporting to supervisors, communications to archive. Immutability and audit trail matter more than throughput, because an integration that cannot evidence what it did is unusable here.
- Digital Transformation Consulting
- The audit usually finds compliance operations absorbing manual work that has been normalised, and onboarding drop-off larger than the growth team believes because it is measured at signup rather than activation.
- Maintenance & Ongoing Support
- Regulatory change is continuous and reporting formats move on legislative timetables. Maintenance here is about remaining compliant rather than remaining available.
What is specific to this sector
Licensed payment and electronic money institutions face supervisory outsourcing requirements that reach their suppliers: notification to the regulator, audit rights, documented processing location and a written exit plan. Lithuania hosts a large licensed population and the Bank of Lithuania supervises accordingly; DIFC and ADGM entities face DFSA and FSRA expectations respectively. This is scope, not paperwork, and it belongs in the first conversation.
Safeguarding of customer funds carries specific operational and reconciliation obligations, and any system touching those flows is in a regulated category. We build around safeguarding rather than into it, and we say so rather than accepting work that should go to a specialist.
Automated decisions on onboarding, creditworthiness or account restriction produce legal or similarly significant effects, engaging GDPR Article 22 and increasingly AI-specific rules. Building in that category requires regulatory input we do not provide, and we would rather decline than caveat.
Strong customer authentication under PSD2 governs when and how a payer must be authenticated, with defined exemptions that carry their own conditions. Authentication design is therefore regulatory design, and exemption logic sits in the payment flow rather than in a policy document — a point that surprises teams treating checkout friction purely as a conversion problem.
The EU instant payments rules introduce verification of payee for credit transfers, requiring the payer to be told whether the account name matches before confirming. That is a user experience obligation with a prescribed outcome, and it changes the payment confirmation screen in ways that must be implemented rather than interpreted.
Not legal or regulatory advice. Sector rules described here are scoping context, current to our latest review. Confirm what applies to your business with a qualified adviser.
Questions
Can you work with a supervised institution?
Yes, and expect the outsourcing paperwork: notification, audit rights, documented processing location, exit plan. We accommodate it as scope. A supplier meeting those requirements for the first time will delay your compliance function considerably.
How do we improve onboarding without weakening controls?
By measuring where drop-off actually happens, which is usually document capture rather than the checks themselves, and fixing the experience around the control rather than removing it. Mobile capture, saved progress and explaining why information is needed recover a lot without touching the control.
Can AI reduce our screening review load?
Triage and prioritisation of alerts, yes, with humans deciding. Automating the decision to clear or escalate is a regulated determination and not something we would build without your specialist input.
What can we say in marketing?
Less than an unregulated competitor, and the landing page is in scope alongside the ad. Educational content is the workable ground, and approval records may need retaining depending on your regulator.
Do you touch the ledger or safeguarding?
No. That is specialist regulated engineering and we build around it — onboarding, reporting, back office, growth — rather than into it.
What metrics will investors actually examine?
Ones that reconcile with the ledger. Active customers, transaction volume, cohort retention and unit economics all need agreed definitions and documented lineage, because "how was this produced" is a diligence question.
What does it cost?
Quoted per phase after a discovery call, with the supervisory documentation overhead scoped explicitly rather than absorbed.
How does DORA affect our suppliers?
The digital operational resilience framework brings ICT risk management, incident reporting and third-party oversight obligations to financial entities, with contractual requirements flowing down to ICT providers. It changes what has to be in supplier contracts and what evidence has to exist, and it is worth confirming your position with your compliance function.
Can we reduce checkout friction?
Within the exemption framework, yes, but the exemptions have conditions and the logic belongs in the payment flow. Treating authentication as a pure conversion problem is how firms end up applying an exemption they cannot justify.