White-label vs custom fintech platform: build, rent or buy

Custom build, SaaS licence or white-label with the source code: how the three routes compare on time, cost, ownership and lock-in, and the outsourcing rules regulators apply to each.

Module blocks marked grid, code and check standing on a platform plate, with a gold key

You can build a fintech platform with your own engineers or an agency, rent a SaaS (software as a service) platform that a vendor runs, or buy a white-label platform and take over its source code. Build when the product works in a way nobody sells. Rent when you want the quickest start without an engineering team, and can accept the vendor's roadmap and fees. Buy the code when you want a quick start and ownership, and can staff a team to run it.

The licence is the same on every route, because regulators license the financial activity, not the software. So is the responsibility: the licensed firm answers for what its suppliers do.

This guide is general information, not legal advice: the details depend on your services and your market, so confirm them with a lawyer and the regulator before you apply.

The three routes

Custom build. Your engineers, or an agency's, write every part: the ledger, onboarding and identity checks, connections to banks, card issuers or custodians, the apps and the backoffice. With an agency, make sure the contract assigns you the code and hands over the repositories.

SaaS or licensed software. A vendor runs, hosts and upgrades its platform under your brand. You configure rather than build, so it is the quickest start. Pricing is a subscription or licence fee, often with a revenue share, for as long as you operate. The code stays with the vendor, features follow its roadmap, and your data sits in its systems on the contract's terms.

White-label with the source code. A vendor's finished platform is configured, branded and deployed on your infrastructure, and you receive its source code, infrastructure configuration and documentation. Afterwards your team, or a contractor you choose, runs, patches and changes it.

Custom build

SaaS platform

White-label with source code

Time to launch

Longest: everything is built first

Short: the platform already runs

Short: a running platform is configured

Cost upfront

Engineering time

Set-up and integration

The scope of the delivery

Cost over time

Your team and hosting

Fees, and any revenue share, while you operate

Your team or contractor, and hosting

Code and data

Yours, if the contracts say so

Code stays with the vendor; data as the contract says

Yours: code, configuration and data

What an exit plan covers

Hosting, and any agency maintaining the code

The whole platform and your data

Hosting, and any support contract

Changes

Anything, at development cost

Settings, and the vendor's roadmap

Anything, by your team or the vendor

What the route does not change

The software rarely sets the launch date. A licence or a licensed partner, a bank for client money, a card issuer and processor for cards, custody and liquidity for crypto, acquirers and a card data security assessment for card acceptance all run on their own clocks. See the guides to EU and UK e-money licences, the EU crypto rules (MiCA) and launching a neobank without a banking licence.

If the vendor, not you, holds the contracts with those providers, leaving it means contracting and onboarding again with each one. For an exchange, ask who controls the keys. Under MiCA, controlling clients' keys is custody, which needs authorisation (Articles 3 and 59), and a custodian may hand custody only to another authorised provider (Article 75(9)).

Outsourcing: the regulator looks through your vendor

EU

DORA, the Digital Operational Resilience Act (Regulation (EU) 2022/2554), has applied since 17 January 2025 (Article 64) to banks, payment and e-money institutions, investment firms and crypto-asset service providers, among others (Article 2). It covers ICT (information and communication technology) services, meaning digital and data services provided on an ongoing basis (Article 3), a definition the European Commission reads broadly (Q&A DORA030). A SaaS platform running your accounts or order book is one; with your own code, your hosting and any support contract are. DORA asks you to:

  • stay fully responsible, and keep a register of all ICT contracts, reporting new ones to your regulator at least yearly (Article 28);

  • tell the regulator in good time before contracting ICT services for a critical or important function, one whose disruption would materially impair your finances, services or compliance (Articles 28(3) and 3(22));

  • write into each contract where data is processed, how you get it back if the provider fails or the contract ends, and your termination rights (Article 30);

  • for critical or important functions, add full service levels, unrestricted audit rights for you and your regulator, and an exit strategy with a mandatory transition period, backed by tested exit plans (Articles 30(3) and 28(8)).

Crypto-asset service providers also need an outsourcing policy with exit strategies, a written agreement they can terminate, and the expertise to supervise what they outsource (MiCA, Article 73).

Banks, payment and e-money institutions also follow the 2019 Guidelines on outsourcing arrangements of the European Banking Authority (EBA): a register of all outsourcing, timely notice to the regulator of planned outsourcing of critical or important functions, and documented exit strategies (paragraphs 52, 58 and 106 to 108). On 18 September 2026 the EBA published final guidelines on third-party risk for non-ICT services, which leave ICT to DORA and will repeal the 2019 guidelines once they apply. On 7 October 2026 they awaited translation, with no application date set.

UK

The outsourcing rules of the Financial Conduct Authority (FCA), in SYSC 8, bind its common platform firms: banks, building societies and investment firms. The firm stays fully responsible, keeps the expertise to supervise the provider, and must be able to end the arrangement and carry on, through another provider or itself, without harming its service to clients (SYSC 8.1.6-A R and 8.1.8 R). Authorised payment and e-money institutions must tell the FCA before outsourcing any operational function, and outsourcing an important one, IT systems included, must not impair internal control or the FCA's oversight (Payment Services Regulations, regulation 25; Electronic Money Regulations, regulation 26). For UK crypto firms, see FCA cryptoasset registration.

The Prudential Regulation Authority's supervisory statement SS2/21, for banks and the other firms it supervises, expects notice before a material outsourcing and tested exit plans for both a provider's failure and a planned exit (paragraphs 5.14 and 10.1). It lists buying the design and build of an on-premise IT platform among third-party arrangements that are not outsourcing, though it still expects firms to assess their risks (2.4 and 2.5). From 18 March 2027, FCA and PRA rules add notice and a register of material third-party arrangements, authorised payment and e-money institutions included (PS26/2).

UAE

Onshore, the Central Bank of the UAE must approve outsourcing by payment service providers and stored value facilities, which remain responsible (Retail Payment Services and Card Schemes Regulation, Article 16; Stored Value Facilities Regulation, Article 8). Dubai's Virtual Assets Regulatory Authority (VARA) expects notice before any new material outsourcing, and may object (Rule IV.H). The contract must give the firm and VARA access to data at any time and a right to terminate, plus exit assistance for material outsourcing (Rule IV.D).

Questions that decide the route

  • Who will run the code after launch? Owning code needs engineers, employed or contracted.

  • Where will the data live? DORA wants the locations in every ICT contract; VARA, in every material outsourcing.

  • What if the vendor fails, reprices or is sold? The exit plans above answer that; write yours before you sign.

What drives the cost

  • Custom build: engineering months before the first customer, security testing, every provider integration, and a permanent team.

  • SaaS: set-up and integration, then fees for as long as you operate, growing with you if they include a revenue share, and a migration if you leave.

  • White-label with code: the scope of the delivery, hosting, and the team or contractor that runs it.

  • Every route: the licence and its capital, provider contracts, compliance staff, audits and penetration tests. See what it costs to launch an exchange.

Common mistakes

  • Comparing year-one cost only. A revenue share is smallest at launch and largest when you succeed.

  • Signing a SaaS contract without DORA's terms. Exit, transition and audit rights are hard to add later.

  • Taking "source code included" on trust. Check for build scripts, infrastructure configuration, documentation and the right to modify and deploy, and that nothing calls a vendor's licence server.

  • No one in-house who can supervise a vendor. MiCA, SYSC 8 and VARA all expect that expertise.

What this means for your platform

Paynoramic sells the third route: platforms assembled from one library of modules already running in production. The software takes about 30 days on a ready platform and 2 to 3 months for a custom assembly. At launch you receive 100% of the source code, the infrastructure configuration and the documentation, with no licence fee and no revenue share. It runs on your infrastructure. Each provider signs its contract with you, and we help you get it; switching provider later means a new connector, not a new app.

Start from our white-label crypto exchange, white-label banking app or white-label payment gateway, or see all our white-label fintech platforms. They are starting points: anything else is assembled from the same modules, from the ledger to compliance reporting.

Sources

Checked on 7 October 2026.

Written by

Paynoramic's Head of IT

Head of IT at Paynoramic, responsible for the module library every platform is built from. Has worked on payment, banking and workforce platforms for companies including American Express, Teya and Indeed Flex, and for a global card issuer-processor. Writes about what a fintech or crypto launch needs beyond the software: licensing, certification and the real cost.