White-label vs custom fintech platform: build, rent or buy
Custom build, SaaS licence or white-label with the source code: how the three routes compare on time, cost, ownership and lock-in, and the outsourcing rules regulators apply to each.

You can build a fintech platform with your own engineers or an agency, rent a SaaS (software as a service) platform that a vendor runs, or buy a white-label platform and take over its source code. Build when the product works in a way nobody sells. Rent when you want the quickest start without an engineering team, and can accept the vendor's roadmap and fees. Buy the code when you want a quick start and ownership, and can staff a team to run it.
The licence is the same on every route, because regulators license the financial activity, not the software. So is the responsibility: the licensed firm answers for what its suppliers do.
This guide is general information, not legal advice: the details depend on your services and your market, so confirm them with a lawyer and the regulator before you apply.
The three routes
Custom build. Your engineers, or an agency's, write every part: the ledger, onboarding and identity checks, connections to banks, card issuers or custodians, the apps and the backoffice. With an agency, make sure the contract assigns you the code and hands over the repositories.
SaaS or licensed software. A vendor runs, hosts and upgrades its platform under your brand. You configure rather than build, so it is the quickest start. Pricing is a subscription or licence fee, often with a revenue share, for as long as you operate. The code stays with the vendor, features follow its roadmap, and your data sits in its systems on the contract's terms.
White-label with the source code. A vendor's finished platform is configured, branded and deployed on your infrastructure, and you receive its source code, infrastructure configuration and documentation. Afterwards your team, or a contractor you choose, runs, patches and changes it.
Custom build | SaaS platform | White-label with source code | |
|---|---|---|---|
Time to launch | Longest: everything is built first | Short: the platform already runs | Short: a running platform is configured |
Cost upfront | Engineering time | Set-up and integration | The scope of the delivery |
Cost over time | Your team and hosting | Fees, and any revenue share, while you operate | Your team or contractor, and hosting |
Code and data | Yours, if the contracts say so | Code stays with the vendor; data as the contract says | Yours: code, configuration and data |
What an exit plan covers | Hosting, and any agency maintaining the code | The whole platform and your data | Hosting, and any support contract |
Changes | Anything, at development cost | Settings, and the vendor's roadmap | Anything, by your team or the vendor |
What the route does not change
The software rarely sets the launch date. A licence or a licensed partner, a bank for client money, a card issuer and processor for cards, custody and liquidity for crypto, acquirers and a card data security assessment for card acceptance all run on their own clocks. See the guides to EU and UK e-money licences, the EU crypto rules (MiCA) and launching a neobank without a banking licence.
If the vendor, not you, holds the contracts with those providers, leaving it means contracting and onboarding again with each one. For an exchange, ask who controls the keys. Under MiCA, controlling clients' keys is custody, which needs authorisation (Articles 3 and 59), and a custodian may hand custody only to another authorised provider (Article 75(9)).
Outsourcing: the regulator looks through your vendor
EU
DORA, the Digital Operational Resilience Act (Regulation (EU) 2022/2554), has applied since 17 January 2025 (Article 64) to banks, payment and e-money institutions, investment firms and crypto-asset service providers, among others (Article 2). It covers ICT (information and communication technology) services, meaning digital and data services provided on an ongoing basis (Article 3), a definition the European Commission reads broadly (Q&A DORA030). A SaaS platform running your accounts or order book is one; with your own code, your hosting and any support contract are. DORA asks you to:
stay fully responsible, and keep a register of all ICT contracts, reporting new ones to your regulator at least yearly (Article 28);
tell the regulator in good time before contracting ICT services for a critical or important function, one whose disruption would materially impair your finances, services or compliance (Articles 28(3) and 3(22));
write into each contract where data is processed, how you get it back if the provider fails or the contract ends, and your termination rights (Article 30);
for critical or important functions, add full service levels, unrestricted audit rights for you and your regulator, and an exit strategy with a mandatory transition period, backed by tested exit plans (Articles 30(3) and 28(8)).
Crypto-asset service providers also need an outsourcing policy with exit strategies, a written agreement they can terminate, and the expertise to supervise what they outsource (MiCA, Article 73).
Banks, payment and e-money institutions also follow the 2019 Guidelines on outsourcing arrangements of the European Banking Authority (EBA): a register of all outsourcing, timely notice to the regulator of planned outsourcing of critical or important functions, and documented exit strategies (paragraphs 52, 58 and 106 to 108). On 18 September 2026 the EBA published final guidelines on third-party risk for non-ICT services, which leave ICT to DORA and will repeal the 2019 guidelines once they apply. On 7 October 2026 they awaited translation, with no application date set.
UK
The outsourcing rules of the Financial Conduct Authority (FCA), in SYSC 8, bind its common platform firms: banks, building societies and investment firms. The firm stays fully responsible, keeps the expertise to supervise the provider, and must be able to end the arrangement and carry on, through another provider or itself, without harming its service to clients (SYSC 8.1.6-A R and 8.1.8 R). Authorised payment and e-money institutions must tell the FCA before outsourcing any operational function, and outsourcing an important one, IT systems included, must not impair internal control or the FCA's oversight (Payment Services Regulations, regulation 25; Electronic Money Regulations, regulation 26). For UK crypto firms, see FCA cryptoasset registration.
The Prudential Regulation Authority's supervisory statement SS2/21, for banks and the other firms it supervises, expects notice before a material outsourcing and tested exit plans for both a provider's failure and a planned exit (paragraphs 5.14 and 10.1). It lists buying the design and build of an on-premise IT platform among third-party arrangements that are not outsourcing, though it still expects firms to assess their risks (2.4 and 2.5). From 18 March 2027, FCA and PRA rules add notice and a register of material third-party arrangements, authorised payment and e-money institutions included (PS26/2).
UAE
Onshore, the Central Bank of the UAE must approve outsourcing by payment service providers and stored value facilities, which remain responsible (Retail Payment Services and Card Schemes Regulation, Article 16; Stored Value Facilities Regulation, Article 8). Dubai's Virtual Assets Regulatory Authority (VARA) expects notice before any new material outsourcing, and may object (Rule IV.H). The contract must give the firm and VARA access to data at any time and a right to terminate, plus exit assistance for material outsourcing (Rule IV.D).
Questions that decide the route
Who will run the code after launch? Owning code needs engineers, employed or contracted.
Where will the data live? DORA wants the locations in every ICT contract; VARA, in every material outsourcing.
What if the vendor fails, reprices or is sold? The exit plans above answer that; write yours before you sign.
What drives the cost
Custom build: engineering months before the first customer, security testing, every provider integration, and a permanent team.
SaaS: set-up and integration, then fees for as long as you operate, growing with you if they include a revenue share, and a migration if you leave.
White-label with code: the scope of the delivery, hosting, and the team or contractor that runs it.
Every route: the licence and its capital, provider contracts, compliance staff, audits and penetration tests. See what it costs to launch an exchange.
Common mistakes
Comparing year-one cost only. A revenue share is smallest at launch and largest when you succeed.
Signing a SaaS contract without DORA's terms. Exit, transition and audit rights are hard to add later.
Taking "source code included" on trust. Check for build scripts, infrastructure configuration, documentation and the right to modify and deploy, and that nothing calls a vendor's licence server.
No one in-house who can supervise a vendor. MiCA, SYSC 8 and VARA all expect that expertise.
What this means for your platform
Paynoramic sells the third route: platforms assembled from one library of modules already running in production. The software takes about 30 days on a ready platform and 2 to 3 months for a custom assembly. At launch you receive 100% of the source code, the infrastructure configuration and the documentation, with no licence fee and no revenue share. It runs on your infrastructure. Each provider signs its contract with you, and we help you get it; switching provider later means a new connector, not a new app.
Start from our white-label crypto exchange, white-label banking app or white-label payment gateway, or see all our white-label fintech platforms. They are starting points: anything else is assembled from the same modules, from the ledger to compliance reporting.
Sources
Checked on 7 October 2026.
EUR-Lex, Regulation (EU) 2022/2554 (DORA), of 14 December 2022: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R2554
EIOPA, joint ESAs Q&A DORA030, final, answer by the European Commission: https://www.eiopa.europa.eu/qa-regulation/questions-and-answers-database/2999-dora030_en
EUR-Lex, Regulation (EU) 2023/1114 (MiCA), consolidated version of 9 January 2024: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02023R1114-20240109
EBA, Guidelines on outsourcing arrangements (EBA/GL/2019/02), applicable since 30 September 2019: https://www.eba.europa.eu/sites/default/files/documents/10180/2551996/38c80601-f5d7-4855-8ba3-702423665479/EBA%20revised%20Guidelines%20on%20outsourcing%20arrangements.pdf
EBA, Final report, Guidelines on the sound management of third-party risk regarding non-ICT services (EBA/GL/2026/09), 18 September 2026: https://www.eba.europa.eu/sites/default/files/2026-09/dc9ccbb3-79b9-493d-b693-c21adeffbcc9/Final%20report%20on%20GL%20on%20third-party%20risk%20management.pdf
EBA, Guidelines on third party risk management, status page: https://www.eba.europa.eu/activities/single-rulebook/regulatory-activities/internal-governance/guidelines-third-party-risk-management
FCA Handbook, SYSC 8.1, version of 23 October 2025: https://handbook.fca.org.uk/handbook/sysc8/sysc8s1
FCA Handbook, Glossary, common platform firm: https://handbook.fca.org.uk/glossary/G1967
legislation.gov.uk, Payment Services Regulations 2017, regulation 25: https://www.legislation.gov.uk/uksi/2017/752/regulation/25
legislation.gov.uk, Electronic Money Regulations 2011, regulation 26: https://www.legislation.gov.uk/uksi/2011/99/regulation/26
Bank of England, PRA SS2/21 Outsourcing and third party risk management, version of November 2024, effective from 31 December 2024: https://www.bankofengland.co.uk/-/media/boe/files/prudential-regulation/supervisory-statement/2024/ss221-november-2024-update.pdf
FCA, PS26/2 Operational incident and third party reporting, 18 March 2026: https://www.fca.org.uk/publications/policy-statements/ps26-2-operational-incident-third-party-reporting
CBUAE Rulebook, Retail Payment Services and Card Schemes Regulation (Circular No. 15/2021): https://rulebook.centralbank.ae/en/rulebook/retail-payment-services-and-card-schemes-regulation
CBUAE Rulebook, Stored Value Facilities Regulation (Circular No. 6/2020): https://rulebook.centralbank.ae/en/rulebook/stored-value-facilities-svf-regulation
VARA, Company Rulebook, Rule IV.D, Outsourcing Agreements, in force from 19 June 2025: https://rulebooks.vara.ae/rulebook/d-outsourcing-agreements
VARA, Company Rulebook, Rule IV.H, Regulatory Notifications, in force from 19 June 2025: https://rulebooks.vara.ae/rulebook/h-regulatory-notifications


