The most expensive mistake in Pakistani fintech is building the product first and asking about regulation afterwards.

Founders regularly arrive with a working app, users, and sometimes revenue — having done something that requires a licence they do not hold. At that point the options are to stop, to restructure the business, or to partner with a licensed institution from a weak negotiating position.

Two regulators, and the line between them

The State Bank of Pakistan (SBP) regulates banking, payments and payment systems, electronic money, and foreign exchange.

The Securities and Exchange Commission of Pakistan (SECP) regulates non-banking finance — including lending outside the banking system — insurance, capital markets and investment services, alongside its general company functions.

Which regulator you fall under is determined by what you actually do with money, not by how the product is described in a pitch deck. Terms like "platform", "marketplace" and "facilitator" carry no regulatory meaning.

Ask these questions before you build

Do you hold or control customer funds? Even briefly, even in transit. Holding customer money is the single most licence-triggering activity in fintech. Structures where funds settle directly between customer and merchant, or sit in a licensed institution's account, are treated very differently.

Do you lend? Lending as a business, from your own or investors' balance sheet, sits within the non-banking finance framework and requires SECP authorisation. "Buy now pay later" and salary advance products are lending, whatever they are called.

Do you issue stored value? A wallet holding a balance is electronic money.

Do you initiate or process payments? Payment initiation, acquiring, aggregation and operating a payment system each carry their own requirements.

Do you take deposits? Deposit-taking is banking, and it is not available without a banking licence. Products offering a "return on balance" need very careful analysis.

Do you offer investments? Advising on, arranging or managing investments engages SECP regulation.

Is it insurance? Any product transferring risk for a premium is insurance, including embedded protection sold alongside another product.

If the honest answer to several of these is "sort of", the position needs resolving before launch rather than after.

The realistic routes to market

Get licensed. Substantial: capital requirements, fit and proper assessment of sponsors and management, governance and risk frameworks, technology and security standards, AML systems, and an application process measured in many months. Regulators also operate sandbox and pilot arrangements at various times, which can be worth exploring.

Partner with a licensed institution. The most common route for early-stage fintechs — the bank, EMI or NBFC holds the licence and the regulatory relationship; you provide technology and distribution. Faster and cheaper, but you are dependent on your partner, and the commercial terms reflect that. Have that agreement drafted properly, with attention to exit, data ownership and liability allocation.

Build something outside the perimeter. Software licensed to regulated institutions, analytics, or infrastructure. A legitimate model, and it must be genuinely outside the perimeter rather than nominally so.

What an application actually requires

Beyond the form: corporate structure and beneficial ownership, capital and its source, sponsor and management fitness, a credible business plan, governance and board arrangements, risk management, an AML/CFT framework — see AML compliance for smaller businesses — technology, security and business continuity documentation, outsourcing arrangements, and consumer protection and complaints handling.

Applications are refused or delayed most often for incomplete beneficial ownership disclosure, inadequate AML frameworks, and business plans that do not match the licence sought.

Data, and cross-border realities

Customer data obligations, and the requirements around where data is hosted and whether it may be processed abroad, need to be resolved before you choose a cloud architecture. Retrofitting is expensive.

Foreign investment into a Pakistani fintech carries its own considerations — registration of inward remittance, sector conditions, and the ability to repatriate later. Get that right at the outset. See getting money out of Pakistan and setting up a company as a foreign investor.

If you have already launched

Do not continue accumulating exposure while you decide. Take advice on where you actually sit, and if you are operating without an authorisation you need, the realistic options are to stop the activity, restructure it so it falls outside the perimeter, or move it onto a licensed partner's rails quickly.

Regulators respond considerably better to a firm that identifies a problem and comes forward than to one discovered later. That is true in most jurisdictions and it is true here.

Practical advice

Resolve the regulatory question before the build, not after the beta. Design the money flow so that you avoid holding customer funds unless you intend to be licensed for it. Budget realistically for the licensing timeline. Build AML in from the start rather than bolting it on. And read any partner bank agreement carefully — it will govern your business.

How the firm can help

We advise on regulatory perimeter — which licence, which regulator, and whether a proposed model requires authorisation at all — and support licence applications before the SBP and the SECP.

We also draft the agreements these businesses depend on: partner institution arrangements, merchant and customer terms, outsourcing and technology contracts, and investment documentation. And we act in regulatory inquiries and enforcement.

If you are building something that touches money in Pakistan, contact the firm at the design stage. It is the cheapest regulatory advice you will ever take.