Trust should be part of the product
Trust is part of how payment infrastructure operates: who is regulated, how funds are safeguarded and how the model stays durable.
A regulated framework, not an informal arrangement
FinXP is a European Electronic Money Institution, authorised and regulated by the Malta Financial Services Authority. This regulated status is central to how we operate. It supports the provision of payment services, e-money services and related payment infrastructure within the scope of our permissions and applicable regulatory requirements.
For clients, this means payment capability is delivered through a regulated framework, rather than an informal or purely technical arrangement. This is particularly important for businesses handling payment accounts, client funds, collections, payouts, card programmes, merchant settlement, embedded finance or platform payment flows.
Each client, product structure and payment flow must still be assessed, approved and implemented in line with applicable legal, regulatory, scheme, risk and operational requirements.
- E-money issuance and payment accounts
- Direct debiting and fund transfers
- Card payment processing and card issuing
- Subject to licence scope and the approved client model
Stefan Haenel, Co-Founder
Four disciplines behind every payment flow
Licensing, safeguarding, monitoring and data protection are not a final-stage approval step. They are part of the product design.
How a responsible payment model goes live
Strong payment infrastructure starts with responsible onboarding. The objective is not friction. It is making sure the payment model is properly understood before it carries real money.
-
01
Understand the business
We review the business, ownership structure, activity, customer base, jurisdictions, transaction flows and risk profile.
-
02
Complete due diligence
Business due diligence, beneficial ownership checks, verification of directors and authorised persons, source of funds assessment and applicable screening.
-
03
Define the controls
Where a model can be supported, we agree the onboarding approach, transaction flows, reporting requirements and escalation routes before launch.
-
04
Launch and monitor
The programme goes live with ongoing transaction monitoring, periodic reviews and clear escalation, so it stays credible as volumes grow.
How FinXP protects client funds and keeps payment models durable
FinXP combines regulated payment infrastructure with practical compliance, operational controls and sector understanding. This helps businesses build payment flows that are not only commercially useful but also structured responsibly from the start.
Safeguarding client funds
As an Electronic Money Institution, FinXP is required to safeguard relevant client funds in accordance with applicable regulatory requirements. In simple terms, safeguarding means keeping eligible client funds separate from FinXP’s own funds. They are not treated as FinXP operating money and are not used to fund FinXP’s business activities. Safeguarding is supported by internal records, reconciliation processes and controls designed to identify, separate and monitor funds subject to safeguarding requirements.
FinXP is not a bank. Funds held with an Electronic Money Institution are not bank deposits and are not protected in the same way as a bank account. Safeguarding is a separate regulatory protection mechanism that applies to relevant funds under the EMI framework.
Onboarding with purpose
Strong payment infrastructure starts with responsible onboarding. Before FinXP supports a client or payment model, we need to understand the business, ownership structure, activity, customer base, jurisdictions, transaction flows and risk profile. This helps us assess whether the proposed model is suitable, what controls are required and how the relationship should be structured.
Onboarding may include business due diligence, beneficial ownership checks, verification of directors and authorised persons, assessment of source of funds, review of websites or platforms, understanding of customer flows and screening against applicable sanctions or risk requirements. The objective is not to create unnecessary friction. It is to make sure the payment model is properly understood before it goes live.
Due diligence and ongoing monitoring
Compliance does not end at onboarding. Payment activity must continue to be monitored so that unusual behaviour, changes in risk or operational issues can be identified and addressed. FinXP applies due diligence and monitoring processes designed to support responsible payment operations. This may include transaction monitoring, sanctions screening, risk reviews, account activity analysis, periodic reviews and escalation of activity requiring further assessment.
Compliance as a buying reason
Compliance should not feel like a barrier to growth. For serious payment flows, it is the structure that helps keep the programme credible and sustainable. A payment model without clear onboarding, monitoring, safeguarding, reconciliation and escalation processes may work at the beginning, but it can become fragile as volumes increase. That is why compliance at FinXP is not treated as a separate department or a final-stage approval step. It is part of the product design.
This page provides a simple, high-level explanation of FinXP's regulatory and safeguarding approach. It does not constitute legal, regulatory or financial advice. The exact treatment of funds and the controls applied may depend on the product, service, transaction type and applicable regulatory requirements.
Safeguarding at an EMI is not the same as a bank deposit
FinXP is regulated as an Electronic Money Institution, not a bank. Here is how EMI safeguarding compares with a bank deposit, side by side.
An Electronic Money Institution (EMI), authorised to issue e-money and provide payment services.
A credit institution, authorised to take deposits and provide banking services.
Client funds are held in safeguarding accounts at regulated credit institutions, kept separate from the EMI's own money.
Customer money sits on the bank's own balance sheet as a deposit.
Through safeguarding: funds are ring-fenced so they stay identifiable as clients' money.
Through a deposit guarantee scheme, up to the limit set by that scheme.
No. Safeguarded funds are not lent out or invested for the institution's own account.
Deposits may be lent out as part of normal banking activity.
Safeguarding accounts are for holding and moving funds, not for earning interest.
Deposit accounts may pay interest, depending on the product.
Built for making and receiving payments, holding balances and running day-to-day money flows.
Built for saving, borrowing and a broad range of banking services.
A general comparison of two regulated models, not financial advice. Protections depend on the specific institution and the rules that apply to it.
Regulated sectors, clear risk criteria
Some sectors are commercially strong but operationally or regulatorily complex. FinXP understands that complexity. We work with businesses where payment flows may require deeper review, clearer controls, stronger monitoring or more careful structuring.
This does not mean every sector, client or model can be supported. It means FinXP is willing to understand the business model rather than reject complexity by default or force every client into a generic payment structure.
Where a model can be supported, we help define the right controls, onboarding approach, transaction flows, reporting requirements and escalation routes before launch.
Controls that stand up to real payment volumes
Reliable payment infrastructure depends on more than access to payment rails. It requires people, processes, systems, monitoring and clear communication when issues occur.
Operational controls
Controls around payment approvals, transaction monitoring, reconciliation, settlement review, fraud checks, dispute handling and incident escalation. The exact controls depend on the product, client model and approved structure.
Operational resilience
Our approach to resilience is designed to support the continuity, oversight and responsible management of payment services: account access, payment execution, reporting, reconciliation and issue resolution.
Clear responsibilities before launch
Before a programme goes live, we clarify who is responsible for onboarding, customer communication, transaction data, support, complaints handling, reporting, reconciliations, fraud controls and escalation. Clear responsibilities reduce risk.
Direct support and clear escalation paths
A merchant needs to know how settlements work. A platform needs to know how balances and payouts are controlled. A fintech needs to know how onboarding and monitoring are structured. We help you answer these questions before you commit, and we define how issues are escalated once you are live.
Understanding CENTROlink: A Beginner’s Guide
It's a payment system, operated by the Bank of Lithuania, that gives financial institutions access to the SEPA payment schemes. Think of it as one of the roads that leads into the SEPA network, rather than SEPA itself.
No. SEPA is the overall framework and set of rules for euro payments across Europe. CENTROlink is a specific system an institution can connect to, providing access to the SEPA infrastructure, not the scheme itself.
A direct participant maintains its own settlement account and a technical connection to CENTROlink, so payments don't pass through another institution first. An indirect participant relies on a direct participant to sponsor its access, an extra link in the chain that can add delay and reduce visibility.
CENTROlink publishes a list of its participants and distinguishes direct from indirect status. You can check any provider's claim against that public list rather than taking their word for it.
A direct participant settles payments itself, with nobody standing between it and the settlement system. An indirect participant routes every payment through a sponsor's own account and systems first, adding a layer that can slow things down or obscure where a payment is.
It affects how quickly and predictably your settlement occurs, how easily a payment can be traced if something goes wrong, and how stable your access is over time. Indirect access depends on a second company's ongoing willingness to sponsor it.
No. It's a payment system operated by Lietuvos bankas, the Bank of Lithuania. It doesn't hold customer accounts itself: it provides the settlement infrastructure that licensed institutions like EMIs and banks connect to.
Lietuvos bankas, the Bank of Lithuania, is Lithuania's central bank and the operator of CENTROlink. A Malta-licensed EMI can still be a direct participant in CENTROlink because SEPA infrastructure operates across borders; the connection isn't limited to institutions based in Lithuania.
Ask directly whether they are a direct or indirect CENTROlink participant and ask them to point you to the published evidence rather than accepting a verbal claim.
Your payments route through an additional sponsoring institution, which can mean slower settlement, reduced visibility if a payment needs tracing, and exposure to that sponsor's decisions about whether to continue supporting the arrangement.
What Is an EMI? A Plain-English Explainer
Electronic Money Institution, a type of business authorised under EU law to issue electronic money, hold payment accounts, and process payments, without being a bank.
No. An EMI can hold and move money on your behalf, but it cannot take deposits or lend money, which is the activity that legally separates a bank from an EMI. Client funds are safeguarded rather than treated as a deposit.
A bank can accept deposits and make loans; an EMI cannot. An EMI issues e-money, operates payment accounts, and can issue cards; the same day-to-day payment functionality a business typically needs, under a lighter but still fully regulated structure.
Client funds at a regulated EMI must always be safeguarded and held separately from the EMI's own money, so they aren't available to the EMI's creditors if the company runs into financial trouble. That's a legal requirement, not a policy choice.
Because safeguarded funds are held apart from the EMI's own balance sheet, they're intended to be identifiable and returnable to clients rather than treated as assets available to general creditors in an insolvency.
Each EMI is licensed and supervised by a national regulator under a shared EU framework; in FinXP's case, the Malta Financial Services Authority. As a result, the underlying rules are harmonised even though supervision sits nationally.
It's the requirement to always keep client funds separate from the EMI's operational funds, and never use them for the EMI's working capital, lending, or investment.
Search the relevant national regulator's public register of licensed institutions for a Malta-licensed EMI; that's the MFSA's register rather than relying on a claim made in the company's own materials.
Often, speed, focus, and sector fit; EMIs are typically faster to onboard and more willing to serve sectors like iGaming, FX, or digital assets that many banks decline outright, while still operating under full regulatory safeguarding requirements.
In this context, they're generally used interchangeably; both mean a regulator has formally approved the institution to carry out specific financial activities. What matters more than the word used is whether you can verify it on the regulator's own register.
Build on a payment partner you can explain internally
Your finance, product, compliance and leadership teams need to understand why a provider is credible. FinXP gives you a clear answer: regulated status, safeguarding, onboarding discipline, ongoing monitoring and operational control.