Deep dive
Licensing models for a payments app
There are three common routes. You can partner with a bank or licensed payment institution that holds customer funds and handles regulatory obligations, while you build the app and ledger. You can become an agent of a licensed provider. Or you can obtain your own licences, which in the US means state money transmitter licences and FinCEN registration, in the UK and EU an e-money or payment institution licence, and in India authorisation from the RBI or an arrangement under NPCI's UPI framework.
Most startups start with a partner. It shortens the path to launch from years to months, though the partner takes a share of revenue and sets rules for your product. Partner due diligence is serious: expect questions about your team, controls, fraud approach and finances. Since several banking-as-a-service failures in recent years, partners and regulators look closely at how fintechs reconcile customer funds, so a sound ledger is part of the sale.
How the ledger keeps every balance right
Every money movement, a payment between friends, a top-up, a withdrawal or a fee, is recorded as balanced entries: one account is debited and another credited by the same amount. Balances are computed from entries, never edited directly. When the partner confirms a bank transfer, a new entry moves the funds from pending to available.
Each API call that moves money carries an idempotency key, so a retry after a timeout never pays twice. Daily reconciliation compares your ledger with the partner's statements and flags any difference for investigation before customers notice.
- Never update a balance column; append ledger entries instead.
- Store amounts as integers in minor units with an explicit currency.
- Reconcile with the partner every day and alert on any mismatch.
Fraud, scams and limits
New accounts start with low limits that rise with verification and good history. Device fingerprinting, velocity checks, behaviour signals and holds on unusual payments stop most early fraud. The feed's social design helps users confirm they are paying the right person, but scams that trick people into sending money remain the hardest problem, which is why warnings and friction on risky payments matter.
In the UK, mandatory reimbursement rules for authorised push payment fraud have raised the cost of scams for payment firms, and similar debates are under way elsewhere. In the scale tier, our machine learning team builds real-time scoring models trained on your own confirmed fraud cases.
Market differences: US, Europe, UK and India
In the US, P2P apps move money over cards and bank transfers, with instant rails such as RTP and FedNow increasingly available through partners. In the EU, instant SEPA transfers and payee name verification are now standard, and the PSD3 and Payment Services Regulation package, politically agreed in 2025, is moving through formal adoption, so plan for updated fraud and liability rules. In the UK, Faster Payments and Confirmation of Payee play a similar role. In India, UPI already offers instant free transfers, so a new app competes on experience as a third-party UPI app through a partner bank rather than on a stored balance.
Pick one market for launch and design the data model for more. Currencies, limits, KYC tiers and disclosures should all be configuration rather than code.
Security, compliance and running costs
Use biometric unlock, device binding, encrypted storage, short sessions for sensitive actions and step-up verification for new payees or large amounts. Keep card data with the partner so your PCI DSS scope stays small. Data protection rules such as the GDPR and India's DPDP Act apply to transaction histories and contact lists, so ask for contacts only when needed.
Running costs include partner fees, KYC checks, SMS and WhatsApp codes, card and transfer fees, cloud and monitoring. Plan roughly 15-20% of the build cost per year for maintenance and support. This page is general information, not legal advice.