Industries we work in
The modules are the same. What changes is the risk that dominates and the counterparty whose approval decides whether you launch.
Sector knowledge is not a marketing claim — it is knowing which three questions a supervisor asks first, which clause a payment provider always negotiates, and which part of the file is usually missing.
Below is how the work differs by vertical. The underlying modules are the same; what changes is the risk that dominates, the counterparties whose approval you need, and the documents they will insist on seeing.
iGaming and betting
Online gaming is regulated nationally across the EU, so the first decision is not “which licence is cheapest” but which markets you intend to serve and what each of those markets requires of a licence-holder. A licence that is inexpensive to obtain and unacceptable to your payment provider has cost you more than a difficult one.
Where matters usually turn
- Regime selection against the target markets, including whether local licensing is required to accept players from a given country.
- Key function holders — compliance officer and MLRO — and the separation of those roles from operational management, which several regulators now require explicitly.
- Supplier and platform agreements: certification obligations, liability for game integrity, and audit rights.
- Player-facing terms, bonus conditions, complaint handling and alternative dispute resolution.
- Responsible gaming and AML obligations, which increasingly drive supervisory attention more than the licence application itself.
Documents we most often produce
- Licence application file and business plan
- AML/CFT policy and risk assessment
- Responsible gaming policy
- Terms and conditions, bonus terms
- Supplier and aggregator agreements
- Complaint and ADR procedure
FinTech, payments and e-money
The distinction between a payment institution and an electronic money institution decides your capital, your safeguarding obligations and the shape of your supervision. It should be settled before the business plan is written, not adjusted afterwards to fit an application.
Where matters usually turn
- Whether the model requires authorisation at all, or falls within an exclusion — and whether that exclusion survives the next product iteration.
- Safeguarding arrangements for client funds, including the accounts, the reconciliation process and the evidence that both work.
- Outsourcing and third-party dependency: the agreements, the exit plan and the supervisor's access rights.
- Governance and the fit-and-proper file for directors and key function holders.
- Preparing for the shift to the revised EU payments framework, where the payment institution and e-money regimes are consolidated and existing firms will need to update their authorisation files rather than reapply from scratch.
Documents we most often produce
- Programme of operations and business plan
- Safeguarding policy and reconciliation procedure
- AML/CFT framework and monitoring rules
- Outsourcing register and agreements
- Fit-and-proper documentation
- Complaints and incident procedures
Virtual assets and CASP
Since the MiCA transitional period closed on 1 July 2026, providing crypto-asset services to clients in the EU without authorisation is not a grey area — national regimes no longer provide cover, and several supervisors have said publicly that unauthorised activity will be treated as such.
Where matters usually turn
- Which services the firm actually provides, since the service list determines the capital class and the obligations that follow.
- Custody arrangements, segregation of client assets and the liability position if keys are lost.
- Travel rule implementation for transfers, including what happens with self-hosted wallets and counterparty verification.
- Market abuse and conflict-of-interest controls for trading platforms.
- Passporting: obtaining authorisation in one member state and notifying the others, rather than filing separately in each.
Further reading: MiCA after the transitional period.
Documents we most often produce
- CASP authorisation file
- Custody and safekeeping policy
- Travel rule procedure
- Market abuse and conflicts policy
- Complaint handling procedure
- ICT and business continuity documentation
Affiliate and performance marketing
Affiliate arrangements sit between two regulated parties and are frequently the least documented part of the chain. When a regulator asks an operator to account for how players were acquired, the affiliate contract is the document that answers — or fails to.
- Network and direct affiliate terms: attribution, traffic quality standards, prohibited sources and the consequences of breach.
- Fraud, chargeback and clawback mechanics that survive a dispute.
- Advertising compliance, including restrictions on how licensed products may be promoted in specific markets.
- Data protection roles between operator and affiliate, and the transfer mechanism where data leaves the EEA.
- Payout structures, invoicing and the tax and reporting consequences of the chosen route.
SaaS, platforms and cross-border groups
Software businesses serving regulated clients inherit their clients' obligations through contract. Enterprise procurement, security questionnaires and processor agreements have become the real gate, and they are passed on paper long before anyone evaluates the product.
- Contract architecture: master agreement, order forms, service levels and support commitments that can be met operationally.
- IP ownership across a distributed team, including contractor assignments that actually transfer rights.
- Controller and processor roles, sub-processor management and international transfer documentation.
- Readiness for enterprise due diligence and for an eventual acquirer, where gaps are priced rather than discussed.
Frequently asked questions
We operate in two of these verticals at once. Is that a problem?
It is common — an operator with an in-house affiliate arm, or a platform that also holds a payment authorisation. The issue is not the combination but whether the group structure separates the regulated activity cleanly enough that a supervisor can see where its perimeter ends.
Do you advise on markets outside the EU?
We advise on EU and UK-facing requirements directly, and coordinate local counsel elsewhere. Where a jurisdiction is outside our direct experience we say so rather than researching it at your expense.
Our vertical is not listed. Should we still write?
Yes, if the business sits inside a regulated perimeter or depends on banking and payment access. If it is outside what we do, we will say so in the first reply and, where we can, point you to someone who does it.
Can you help before we have chosen a market?
That is the best moment. Market choice determines authorisation, capital and banking acceptance, and it is far cheaper to model those before commercial commitments than to unwind them afterwards.
Tell us what you are building
A short description of the product, the markets and the payment flows is enough for us to say what is required, in what order and at what cost.
Describe your matter
We reply within one business day with a scope, the deliverables and an indicative fee — not a brochure.