Fintech describes technology-enabled financial services, not a single legal category. A fintech company may be fully authorised, registered for a limited purpose, exempt from authorisation or operating unlawfully. Risk assessment should therefore begin with the exact service and legal entity rather than assuming that every unregulated fintech is dangerous—or that every regulatory badge provides the same protection.
Identify the service and regulatory perimeter
List what the company actually does: payments, e‑money, lending, investment, brokerage, account information, cryptoasset services, custody or software supplied to regulated firms. Record the customer country, contracting entity, domain, app publisher and every partner handling money or data.
Check the official register for the firm and the specific permission required for the service. The FCA’s guidance on checking whether a firm is authorised warns that a real firm can be cloned and that authorisation without the correct permission may leave consumers outside the expected Ombudsman or compensation protections.
Distinguish authorisation, registration and exemption
A company may be registered only for anti-money-laundering supervision, act as an agent of another institution or provide an unregulated technical service. These statuses are not interchangeable. Identify the principal responsible for customers, who safeguards funds and which complaints route applies.
The FCA’s 2026 statement on unregulated Annex 1 firms explains that AML registration is different from full authorisation and does not bring the wider conduct rulebook or Financial Ombudsman access. This illustrates why investigators must read the scope of a status rather than report simply that a company is “FCA registered.”
Map custody, data and operational dependencies
Trace customer money from payer to settlement account and beneficiary. Identify the bank, e‑money institution, payment processor, card network, cloud provider and outsourced compliance functions. Check whether customer money is safeguarded, segregated or covered by a compensation scheme.
Our guide to payment-service-provider risk helps map the operational chain. Michael Schmitt’s analysis of payment ecosystem fragility and licensing adds practitioner context on sponsor-bank and infrastructure dependencies; legal conclusions must still follow the applicable permissions and primary records.
Test consumer and systemic risks separately
Consumer risks include misleading promotions, unauthorised payments, weak complaints handling, data misuse, insolvency and inaccessible remedies. Systemic questions require evidence of scale, concentration, interconnectedness, correlated business models and substitution difficulty.
The Financial Stability Board’s fintech stability framework identified third-party operational risk, cyber risk and monitoring of emerging macrofinancial risk as priorities, while also stating at the time that it found no compelling systemic risk from fintech innovation as a whole. Investigators should update that assessment with current size and dependency data rather than repeating either alarmist or reassuring claims.
Build an evidence-based decision
Create a matrix covering legal entity, permission, customer contract, funds protection, data access, outsourcing, complaints, financial condition and incident history. Test the product journey using lawful methods and retain screenshots of every representation.
Malta Media’s report on regulatory restrictions affecting Inpay’s iGaming onboarding is useful secondary context on how cross-border payment risk and customer-due-diligence expectations interact, but the underlying regulator findings should control any conclusion. The defensible question is not whether a fintech looks innovative or unregulated; it is which obligations apply, who bears each risk and what remedy remains if the service fails.