Payment Partner Due Diligence for European Fintech Startups
A practical guide to payment service provider due diligence for European fintech startups: regulatory checks, AML duties, safeguarding, contracts, and a working checklist.
This article provides general information about payment service provider due diligence for European fintech startups. It is not legal advice. Speak with qualified counsel and a licensed compliance adviser before you sign any partner contract or file a regulatory notification.
Why Payment Partner Due Diligence Matters
Payment partners sit at the centre of a fintech’s money flow. They can hold client funds, touch cardholder data, and act as a regulated interface between the startup and the wider financial system. A weak partner can expose the fintech to lost settlements, frozen accounts, sanctions breaches, regulator scrutiny, and reputational harm.
European supervisors expect fintechs to know who they contract with. Under the EU Payment Services Directive (PSD2) on EUR-Lex, payment activities are regulated activities. A firm that plugs into a payment partner without checks is still accountable for how customer money is handled and reported. Careful payment service provider due diligence is therefore both a legal exercise and a commercial safeguard.
Fintech founders often treat integration timelines as the priority. Due diligence looks slower, but it usually shortens the overall path to launch. A partner that later fails a scheme audit, loses its licence, or refuses a business line can force a full migration months after go-live.
Acquiring Banks, PSPs, Gateways, Processors, and Local Methods
Payment partners are not interchangeable. Each type carries different permissions, obligations, and commercial terms.
- Acquiring banks hold a card scheme licence and settle card transactions with the merchant. They carry chargeback liability and set risk appetite.
- Payment service providers (PSPs) are usually authorised payment institutions or electronic money institutions. They may acquire, issue, initiate payments, or hold e-money on behalf of users.
- Gateways route transaction data between the merchant and the acquirer. Many gateways are not regulated because they do not touch funds.
- Processors handle authorisation, clearing, and reporting on behalf of an acquirer or issuer. They are often technical vendors under a regulated principal.
- Local payment method (LPM) providers connect fintechs to bank transfers, wallets, and instant payment rails in specific markets, such as iDEAL, Bancontact, BLIK, or Pix.
The same brand can play more than one role. A single provider might be a PSP in one country, a gateway in another, and a reseller of a third party’s licence elsewhere. Ask for a role-by-role breakdown before you compare quotes.
How Your Business Model Affects Partner Selection
The right partner depends on how money actually moves in your product. A subscription SaaS with recurring cards has very different needs from a marketplace splitting funds between sellers, a crypto on-ramp, or a wallet holding customer balances.
Map the flow first. Who pays, who receives, when funds settle, and which entity legally holds the balance at each step. Then match the flow to a partner type. A marketplace, for example, usually needs a partner with a payment facilitator or split-payment product, not a plain card acquirer.
Cross-border flows and the currencies you accept also shape the shortlist. A partner that is technically capable in Germany may not offer euro settlement in Poland, or may refuse merchants in your MCC category. Aligning your business model with the partner’s permissions is the earliest and cheapest place to filter candidates.
Verifying Regulatory Status and Permissions
Never rely on a partner’s marketing site for its regulatory status. Confirm the legal entity, its home regulator, the specific permissions it holds, and any passporting rights into the countries where you operate. The EBA register of payment and electronic money institutions lists authorised payment and e-money firms across the EEA and is a useful cross-check against a partner’s claims.
Confirm the services the partner is authorised to provide. PSD2 recognises distinct services such as execution of payment transactions, issuing payment instruments, acquiring, and payment initiation. A firm authorised for one is not automatically authorised for another. Ask for a copy of the licence and the list of activities recorded in its home register.
If the partner passports services into your market, check the host regulator’s public register too. Confirm the notification is current and covers the services you plan to buy. For non-EEA providers, understand which entity contracts with you, where the funds sit, and which court and regulator you would deal with in a dispute.
AML, KYC, Sanctions, and Transaction Monitoring
Anti-money-laundering rules apply to both the fintech and the partner, but they do not lift responsibility off the fintech. Under the EU AML framework, an obliged entity remains liable for its own onboarding, monitoring, and reporting even when it outsources parts of the process.
During due diligence, ask the partner to describe its AML programme in detail. Focus on customer risk assessment, ongoing monitoring, sanctions screening, adverse media checks, escalation, and suspicious activity reporting. Request a summary of its most recent independent AML audit and any regulator findings.
Clarify the division of duties. In many partnerships the fintech handles direct customer KYC while the partner handles merchant or beneficiary screening. Any grey area should be resolved in the contract with a named process, not left to goodwill. Sanctions screening in particular should be tested against realistic scenarios before launch.
Safeguarding, Settlement, and Reserves
Where customer funds are held matters as much as how they move. Authorised payment institutions and e-money institutions must safeguard client funds, typically through segregated accounts at a credit institution or through a qualifying insurance policy. Ask the partner where safeguarded funds sit, at which bank, and under which arrangement.
Settlement mechanics come next. Confirm the settlement cycle, the currencies, and any rolling reserves the partner will apply. A ten per cent rolling reserve on a low-margin business can crush cash flow, and reserve policies often change after the first few months of live volume. Get the reserve, hold, and reversal rules written into the contract.
Understand what happens if the partner fails. A well-drafted safeguarding regime should return client funds to customers, not to the partner’s general creditors, but the practical timeline can still be long. Plan for continuity, including a secondary partner that can accept transferred flows.
Data Protection, PCI DSS, and Outsourcing
Payment partners process significant volumes of personal data, so GDPR obligations run alongside financial regulation. Agree the role each party plays: controller, processor, or joint controller. Sign a data processing agreement that reflects Article 28 requirements, cross-border transfer safeguards, and clear breach notification timelines.
If cardholder data flows through your systems, confirm the PCI DSS scope carefully. Many fintechs use tokenisation or hosted fields precisely to keep themselves out of scope. The partner should provide a current Attestation of Compliance and describe how their environment segments cardholder data.
Payment activities are usually classified as important or critical outsourcing under EU guidance. That triggers documentation duties, exit plans, subcontractor controls, and regulator access rights. Confirm the partner accepts audit clauses, provides exit assistance, and lists all material subcontractors, including data centre locations.
Contractual Points That Decide the Relationship
The commercial contract is where due diligence becomes enforceable. Push back on generic templates: payments contracts benefit from tailored terms, and reputable partners expect the negotiation.
Prioritise the clauses that decide continuity and accountability: termination triggers, notice periods, transition assistance, service level commitments, liability caps, indemnities, subcontractor changes, and regulator access. Pay close attention to how the partner can suspend or restrict the service, and to any right you have to migrate merchants and cardholder tokens to another provider.
Data rights deserve their own attention. Confirm you can extract transaction data in a usable format on exit and that dispute records, KYC files, and safeguarding history stay accessible for the periods your regulator requires.
Geographic Coverage, Currencies, and Restricted Models
A partner’s coverage list is not the same as its willingness to serve your business. Many providers restrict certain jurisdictions, currencies, or business models regardless of technical capability. Get the restricted list in writing during diligence, not after go-live.
For European fintechs, local payment methods drive conversion. If you sell in the Netherlands, iDEAL matters more than card art. Ask which LPMs the partner offers directly, which it resells, and what the settlement mechanics look like for each. A partner that resells LPMs through a chain of subcontractors adds counterparty risk.
Once your legal, regulatory, geographic, and operational requirements are defined, an independent payment agency can help identify shortlisted acquirers, PSPs, gateways, and local payment method providers and facilitate introductions on your behalf. Finance Studio, for example, operates as an independent payment agency and ISO that runs matched partner searches for fintechs across Europe, working alongside a founder’s own legal and compliance leads rather than replacing them.
Operational Resilience, Reporting, and Support
Under the EU Digital Operational Resilience Act (DORA) and existing outsourcing guidance, fintechs must manage ICT and operational risk from third-party providers. That means real evidence, not marketing decks. Ask for uptime history, incident post-mortems, recovery point and recovery time objectives, and a summary of business continuity testing.
Day-to-day reporting quality often decides whether a partner scales with you. Reconciliation files, dispute exports, refund workflows, and settlement reports should be complete, timely, and machine-readable. Poor reporting turns into a hidden operational cost that grows with volume.
Support responsiveness matters as much as tooling. Confirm the support model, escalation paths, named contacts, and out-of-hours coverage. Verify these in writing rather than in a sales call.
Warning Signs During Onboarding
Certain patterns during onboarding tend to predict trouble later. Take them seriously.
- Reluctance to name the contracting legal entity or share its licence details.
- Vague or shifting answers about safeguarding accounts and settlement banks.
- A refusal to disclose material subcontractors or data centre locations.
- Contract drafts that omit termination assistance, audit rights, or regulator access.
- Pressure to accept undisclosed rolling reserves or unilateral change rights.
- Unclear ownership of KYC files, dispute records, and cardholder tokens.
- Recent regulator enforcement action that the partner has not proactively disclosed.
A Practical PSP Due Diligence Checklist
Use this checklist as a working document during vendor assessment. Adapt it to the partner’s role and your product.
| Area | What to confirm |
|---|---|
| Legal entity | Registered name, group structure, ultimate beneficial owners, and contracting entity. |
| Licence | Authorised services, home regulator, passporting rights, and current standing. |
| Safeguarding | Segregated accounts, safeguarding bank, insurance arrangement, and reconciliation cadence. |
| AML and sanctions | Programme summary, screening tools, escalation, and latest independent audit. |
| Data protection | Controller or processor role, DPA, cross-border transfer basis, and breach timelines. |
| Security | PCI DSS scope and Attestation of Compliance, ISO 27001 or SOC 2 status, and pen-test cadence. |
| Resilience | Uptime history, RPO and RTO, incident history, and business continuity testing. |
| Commercials | Pricing, reserves, holds, chargeback fees, minimums, and revenue share terms. |
| Contract | Term, termination, SLAs, liability caps, indemnities, and exit assistance. |
| Support | Named contacts, escalation, out-of-hours cover, and issue-resolution SLAs. |
Questions to Ask Before Signing
- Which legal entity are we contracting with, and under which regulator?
- Which services are we buying, and are you authorised for each in the relevant countries?
- Where are safeguarded funds held, and how is safeguarding verified and reported?
- How are AML, sanctions, and monitoring duties split between us in writing?
- What are the settlement cycle, currencies, reserves, and holds we should plan for?
- What subcontractors are involved, and where do they process our data?
- What happens on exit or partner failure, and how do we retrieve data and funds?
- What SLAs apply, and what remedies do we have when they are missed?
- Which of our business categories or countries could you later restrict?
- Can we review your latest independent audit and any open regulator matters?
Closing Thoughts
Payment partner due diligence is not a one-off procurement exercise. It is a repeating discipline that keeps a fintech aligned with its regulator, its scheme rules, its investors, and its customers as it grows. A structured approach turns a stack of legal, financial, and operational questions into a documented decision that a board or a supervisor can follow.
Startups that invest early in a proper payment partner review tend to avoid the migrations, freezes, and enforcement scares that consume so much fintech engineering time. The upfront work is modest compared with the cost of picking a partner that cannot grow with the business.
Frequently asked questions
- What is payment service provider due diligence?
- It is the structured review a fintech runs on an acquiring bank, PSP, gateway, processor, or local payment method provider before signing. It covers legal, regulatory, financial, security, and operational fitness.
- How do I verify a European payment partner is authorised?
- Check the home regulator's public register and the EBA register of payment and electronic money institutions. Confirm the exact services authorised and any passporting rights into your markets.
- Who is responsible for AML if my PSP handles onboarding?
- Both the fintech and the PSP have obligations. Under the EU AML framework, an obliged entity remains responsible for its own onboarding, monitoring, and reporting even when parts are outsourced.
- What safeguarding arrangements should a PSP have?
- Authorised payment and e-money institutions must safeguard client funds, usually through segregated accounts at a credit institution or a qualifying insurance policy. Ask for the safeguarding bank, the method, and the reconciliation cadence.
- What should a PSP contract always include?
- At minimum: clear services, SLAs, safeguarding terms, data protection and audit rights, subcontractor disclosure, termination triggers, exit assistance, and liability provisions calibrated to the risk.
- How often should we review payment partners?
- Treat it as a continuous programme. Refresh core diligence at least annually, on any material change (licence, ownership, subcontractors), and whenever your product enters a new market or business line.