Author: Adam Richards

Payments as a Service: the complete guide for businesses outsourcing payment infrastructure in Europe

Payments as a Service (PaaS) DiPocket

Payments as a Service (PaaS) is a model in which a regulated third-party provider supplies the complete payment infrastructure a business needs, delivered through an API-based platform. The business accesses that infrastructure without needing to build, licence or maintain it independently, whether the goal is issuing cards, disbursing funds, processing payments or all three.

This guide covers the full picture: what PaaS is; who uses it; what a provider takes on; how to make the build versus outsource decision; and how to assess provider stability in a European market that has changed significantly since 2022.

*If your evaluation has already led you to card issuance as a specific requirement, see our guide BIN sponsorship explained: the complete guide for fintechs and PSPs. BIN sponsorship is the card scheme participation arrangement that sits within a PaaS model where cards are involved.

What is Payments as a Service (PaaS)?

PaaS, BaaS (Banking as a Service) and embedded finance are terms used frequently and often interchangeably across the market, including by providers who offer all three.

Payments as a Service

PaaS refers specifically to the outsourcing of payment infrastructure: the technical and regulatory layer that enables a business to make and receive payments, issue cards, settle transactions and manage compliance. A PaaS provider holds the regulatory licences, scheme memberships and processing infrastructure, and makes them available to clients through an API. The client pays for access to that infrastructure rather than building and maintaining it.

Embedded finance

Embedded finance is the broadest category: the integration of any financial product or service into a non-financial platform. A retail app offering buy-now-pay-later, a mobility platform offering insurance, or a marketplace offering instant merchant payouts, are all using embedded finance. PaaS is the infrastructure model that often powers embedded finance. BaaS may also be involved where the product requires banking-grade capability.

Banking as a Service

BaaS is a broader term that typically covers the outsourcing of full banking infrastructure, including deposit accounts, lending and credit facilities, not just payment capability. BaaS providers are usually banks or banking licence holders.

In Europe, the BaaS model has attracted significant regulatory scrutiny since 2022. Providers have faced fines, licence restrictions or insolvency as a result of compliance failures relating to banking-grade infrastructure operated at scale without adequate controls. A business using PaaS to issue cards, disburse funds or process payments has no need for banking infrastructure such as deposit accounts, credit facilities or a banking licence.

PaaS serves an entirely different set of requirements, and a well-regulated PaaS provider operates under a different and more focused regulatory model.

The practical decision rule:

If you need to issue cards, process payments, disburse funds or manage payment flows, that is PaaS territory. If you need deposit accounts or credit products, you are in BaaS or banking territory. If you are embedding financial products into a non-financial platform, you are building embedded finance, and PaaS is likely to be the most suitable underlying infrastructure model.

Who uses Payments as a Service?

DiPocket has operated payment programmes across 15 European markets since 2017, working with organisations across a wide range of sectors and use cases. The common thread is not the type of business but the need: access to compliant, scheme-connected payment capability without the overhead of building or licencing it independently.

Fintechs and digital financial businesses

Fintechs launching card products, digital wallets or payment programmes use PaaS to access the complete payment infrastructure stack: processing, compliance, settlement, reporting and scheme connectivity. Rather than building each layer independently, the full operational weight of running a payment programme sits with the provider, so the fintech can focus on its product and customers.

Where a programme involves issuing cards, that infrastructure includes BIN sponsorship: the arrangement through which the provider’s principal membership of Visa and Mastercard is extended to the client, enabling them to issue cards without holding direct scheme membership themselves. PaaS is the full operational model; BIN sponsorship is the card issuance piece within it. A fintech using a PaaS provider for funds disbursement or open banking may not need BIN sponsorship at all.

Platforms and marketplaces

Platforms that need to pay workers, merchants or partners use PaaS to manage payout flows at scale. For this buyer, the core value is operational: payments leave the platform instantly, settle in the recipient’s local currency, and carry configurable controls on how and where funds can be spent. None of that requires the platform to build or licence payment infrastructure itself.

Non-financial businesses embedding payment products

Non-financial businesses across a wide range of sectors use PaaS to embed payment capability into their core operations without needing in-house payment expertise or regulatory licences.

Travel agencies issuing virtual procurement cards, employee benefit platforms issuing prepaid cards, insurance companies disbursing claims and NGOs distributing relief funds are all examples of this model in practice.

Financial institutions extending their product range

Established banks and financial institutions also use PaaS to extend their product range without building new infrastructure internally.

A bank that wants to offer prepaid corporate cards to SME clients, or a lender that wants to disburse loans directly to a branded card, accesses that capability through a PaaS provider rather than building the issuing and processing layer from scratch.

The PaaS model complements rather than competes with existing banking infrastructure.

What does a Payments as a Service provider cover?

One of the most frequent misconceptions about PaaS is how much of the operational and compliance burden the provider absorbs. In a full-service PaaS model, the answer is most of it. Here is what clients should expect a serious provider to cover, and where the boundary with the client’s own responsibilities lies.

What stays with the client

PaaS does not remove all compliance obligations from the client. The client remains responsible for KYC (Know Your Customer) and customer onboarding, the cardholder relationship and customer support, programme design decisions such as spend controls and card configuration, and compliance with any sector-specific regulations that apply to their own business.

The programme agreement between provider and client sets this division out explicitly – it is one of the most important documents in any PaaS arrangement, and any ambiguity creates risk for both parties.

What the provider covers

A full-service PaaS provider holds the regulatory authorisations that make payment activity legal across the markets where the client operates. In Europe, this means an Electronic Money Institution (EMI) licence issued by a recognised financial regulator: the FCA in the UK, the Bank of Lithuania in the EU, or equivalent. Beyond the licence, the provider holds principal membership of Visa and Mastercard, operates the processing infrastructure that authorises transactions in real time, maintains PCI DSS compliance for the card data environment, oversees AML monitoring and fraud detection across all programmes, implements card scheme rule changes, and manages settlement and reconciliation through its banking relationships.

In practice, this means the client does not need to employ compliance officers to manage scheme rules, technology teams to maintain processing infrastructure, or legal resource to track regulatory change. Those functions are in the provider’s remit, covered by their operational capability and their regulatory obligations.

Function PaaS provider Client
Regulatory licences (EMI) Provider holds these Client may need own licence depending on business model
Scheme membership Provider holds principal membership Client operates as affiliate under provider’s BINs
Card issuance and processing Provider Client specifies product requirements
AML monitoring (infrastructure) Provider Client responsible for KYC on its own customers
Scheme rule compliance Provider Not required of client
PCI DSS Provider’s certified environment Client must not store raw card data independently
Settlement Provider manages scheme settlement Client manages its own accounts and reporting
Cardholder relationship Not the provider’s responsibility Client owns the customer relationship
Programme design Provider configures to client specification Client determines product rules and limits

How to assess the stability of a PaaS provider

Choosing a PaaS provider is a longer-term commitment than most buyers realise at the point of signing. If a provider runs into regulatory difficulty, your programme cannot grow. If they face financial trouble, your settlement chain is at risk. If they lose their licence, your programme stops. These issues have arisen for real clients of real providers in the European market in the past three years.

What has happened in the European market

The European market has seen significant consolidation since 2022. Several providers have faced regulatory sanctions, operational failures or loss of licence, with direct consequences for the clients whose programmes ran on their infrastructure: disrupted onboarding, settlement uncertainty and reputational association with a provider under regulatory sanction. The lesson is that the financial and regulatory standing of a PaaS provider is a core commercial risk factor for the client.

Why DiPocket’s model is built the way it is

DiPocket holds dual regulatory authorisation: FCA-regulated in the UK and Bank of Lithuania-regulated in the EU. That is a deliberate structure that gives clients legal certainty in both major European jurisdictions and removes the single-regulator dependency that has caused problems elsewhere. We have maintained that dual structure since our founding in 2015 and have never been subject to regulatory sanctions or restrictions on our operations.

What to look for when choosing a Payments as a Service provider

These criteria are drawn from DiPocket’s experience of both operating as a PaaS provider and of working with clients who have migrated from previous providers. They reflect what actually matters when a programme is live, not just at the point of signing.

1. Dual regulatory authorisation

A provider authorised in both the UK (FCA) and an EU member state (Bank of Lithuania, for example) can serve programmes across both jurisdictions without additional arrangements. A provider with only one authorisation has a geographic ceiling that may constrain your programme as it grows.

2. Principal membership of both Visa and Mastercard

Scheme membership with a single network limits your options at launch and over time. Principal membership of both gives flexibility to issue on either scheme and to respond to changes in commercial terms or product requirements. For clients where card issuance is the specific requirement, principal scheme membership is where BIN sponsorship becomes directly relevant.

3. Length of regulatory track record

How long has the provider held its licences and operated programmes? A provider with a decade of clean regulatory history is materially lower risk than one that obtained its licences recently. Ask specifically whether the provider has ever been subject to regulatory sanctions, restrictions on new business, or special supervisory measures.

4. Financial standing

A PaaS provider is a regulated entity in your settlement chain. Ask about capital adequacy and financial backing. A provider who cannot answer this question clearly may be worth further investigation.

5. Processor flexibility

Some PaaS providers are tied to a single issuer processor. If that processor cannot support a requirement that emerges as your programme grows, you have no recourse short of migrating the entire programme. A provider who works with multiple processors (and is transparent about which ones) gives you flexibility at both launch and scale. DiPocket works with multiple processors including Thredd, and the processing layer can be structured around the client’s requirements rather than the provider’s preferred infrastructure.

6. European market footprint

If your programme will operate across multiple European markets, the provider needs regulatory authorisation and operational experience in each of those markets, not just a single jurisdiction with a passporting claim. DiPocket operates programmes across 15 European markets and settles in EUR, GBP, PLN, HUF and RON directly, without requiring FX conversion steps that add cost and complexity.

7. Advisory capability and programme support

decisions that determine whether a programme succeeds, such as card design, product rules, compliance framework, and go-to-market sequencing, require expertise that most clients do not have in-house. Ask what programme support looks like in practice and who your day-to-day contact will be.

8. Pathway to direct scheme membership

Even with no immediate plans to pursue principal scheme membership, a provider who actively supports that transition is a better long-term partner than one with no interest in it. DiPocket has supported multiple clients through that journey. The transition is operationally significant and considerably smoother with a provider who has done it before.

How DiPocket delivers Payments as a Service

DiPocket was founded in London in 2015 with a deliberate design: a dual-regulated EMI, principal member of both Visa and Mastercard, operating across the EEA and UK from a single integrated platform. We built the model we would have wanted as clients ourselves: one where the regulatory standing was unambiguous, the infrastructure was genuinely owned rather than resold, and the advisory support was built into the service rather than charged as an add-on.

Since 2017 we have operated card programmes across 15 European markets for clients ranging from early-stage fintechs to established financial institutions and large non-financial businesses. Our infrastructure is supported by tier-one technology partners including Thredd for processing, Entersekt for ACS, and ComplyRadar for transaction monitoring.

What DiPocket’s PaaS service covers

  • Associate or affiliate membership of Visa and/or Mastercard under DiPocket’s principal membership
  • Plastic and virtual card issuance, including tokenisation for Apple Pay, Google Pay and other mobile wallets
  • IBAN issuance for payment receipt via SEPA (Single Euro Payments Area) and UK Faster Payments
  • Push-to-card disbursement via Visa Direct and Mastercard Send
  • Transaction fraud monitoring and AML (Anti-Money Laundering) control through integrated compliance infrastructure
  • Multi-currency settlement in EUR, GBP, PLN, HUF and RON
  • Open banking capability via PIS (Payment Initiation Services) and AIS (Account Information Services)
  • API-based integration with detailed reporting and reconciliation
  • Active programme support and advisory guidance throughout the programme lifecycle

Ready to explore Payments as a Service with DiPocket?

DiPocket is a dual-regulated EMI and principal member of both Visa and Mastercard, authorised by the FCA (Reference No. 900439) and the Bank of Lithuania (Licence No. 75), operating payment programmes across 15 European markets. Speak to our team about your programme requirements.

FAQs on Payments as a Service

1. Is Payments as a Service only for fintechs?

No. PaaS is used by organisations across a wide range of sectors: non-financial businesses embedding payment capability, platforms managing payout flows, established financial institutions extending their product range, and fintechs building new payment products. The model is defined by the need to access compliant payment infrastructure without building it, not by the type of business that has that need.

2. What is the difference between a PaaS provider and a payment gateway?

A payment gateway enables a merchant to accept card payments at the point of sale. A PaaS provider supplies the infrastructure that enables a business to issue cards, manage payment flows and settle transactions. The two operate at different levels of the payment stack and are not substitutes for each other.

3. Do I need my own EMI licence to use a PaaS provider?

Not necessarily, but it depends on your business model. If you are holding customer funds or operating as an e-money issuer in your own right, you may need your own EMI authorisation regardless of the PaaS arrangement. The FCA’s guidance for EMI applicants sets out the relevant thresholds for UK businesses. This is a question to work through with your provider and your legal advisers before launch.

4. How long does it take to go live with a PaaS provider?

For a straightforward card programme, two to three months from signed agreement to live issuance is realistic with a well-organised provider. Disbursement-only programmes can move faster. Multi-market launches or programmes requiring extensive customisation will take longer. The bottlenecks are usually compliance sign-off and integration rather than scheme registration.

5. What happens to my programme if my PaaS provider runs into regulatory trouble?

This is the most important risk question a buyer can ask, and the one most content in this space avoids. If a provider is restricted by a regulator from onboarding new clients, your programme cannot grow. If the provider faces financial difficulty, your settlement chain is at risk. If the provider loses its licence, your programme ceases until new infrastructure is found and cards are re-issued to every active cardholder. The best protection is choosing a provider with a long, clean regulatory track record, sound finances, and dual authorisation across the markets you need.

6. Can I use the same PaaS provider across multiple European markets?

Yes. A single PaaS provider can cover multiple European markets provided they hold the necessary regulatory authorisation and have operational infrastructure in each. Passporting an EMI licence across the EEA is legally possible but is not the same as having direct settlement capability and active programme experience in a market. Ask the provider specifically which markets they settle in directly, which currencies they support without FX conversion, and where they have live client programmes running.

What is the difference between principal membership and affiliate membership?

What is a BIN in payment card issuing

Principal members hold a direct contractual relationship with the card scheme, own their BIN ranges, and bear full settlement and compliance responsibility. Affiliate members – also called associate members – operate under a principal member’s umbrella, accessing the scheme through that principal’s BIN without holding a direct scheme relationship themselves. The distinction defines the compliance hierarchy, the settlement chain, and ultimately who is accountable to Visa or Mastercard for every transaction on a programme.

On this page:

What can a principal member do that an affiliate member cannot?

Answer

A principal member can own BINs, settle transactions directly with the scheme, sponsor other businesses as affiliate members, and acquire merchants. An affiliate member can issue cards and process transactions, but cannot own BINs, cannot settle directly with the scheme, and cannot sponsor other businesses to issue cards.

The principal member’s position in the hierarchy

Principal members sit at the top of the card scheme membership hierarchy. They hold a direct contractual relationship with Visa or Mastercard, are assigned BIN ranges by the scheme, and are directly accountable to the scheme for compliance across all cards and transactions associated with their BINs. That accountability extends to any affiliate members operating under their sponsorship – a principal member is responsible for the conduct of the programmes it sponsors.

This means principal members carry both significant operational capability and significant liability. They can build and run card programmes at scale without depending on any other institution. They can also generate revenue by sponsoring others. But they bear the full weight of scheme compliance, settlement exposure, and scheme fees directly.

What affiliate members can and cannot do

Affiliate members – registered with the scheme under a principal member’s sponsorship – can issue branded payment cards and process cardholder transactions. They have a scheme registration, which is real and meaningful: their programmes are recognised by the scheme and transactions flow legitimately through the network.

What they cannot do is operate independently of their sponsor. They cannot settle directly with the scheme – settlement flows through the principal member. They cannot hold BINs in their own name. They cannot sponsor other businesses. And if their principal sponsor ceases to operate or terminates the relationship, their card programme ceases with it until a new sponsor is found.

What to watch for

  • When evaluating a BIN sponsor, confirm they hold principal membership – not affiliate or associate membership – of the relevant scheme. An affiliate cannot legitimately sponsor other businesses to issue cards under a BIN it does not own.
  • Some consultancies and intermediaries position themselves as programme managers without clarifying their actual scheme membership status. Always ask to see the scheme membership confirmation directly.

What are the eligibility requirements for principal membership?

Answer

To become a principal member of Visa or Mastercard in Europe, a business must hold a regulatory licence – either an Electronic Money Institution (EMI) licence or a banking licence – issued by a recognised European financial regulator. The scheme will also assess the applicant’s financial standing, operational infrastructure, compliance framework, and the viability of the proposed programme.

The regulatory prerequisite

A Payment Institution (PI) or Electronic Money Institution (EMI) licence is a prerequisite for any card scheme principal membership application in Europe. The FCA in the UK and the Bank of Lithuania are the two most commonly used licensing authorities for European card programme operators. Obtaining the licence typically takes 12 to 18 months on its own, before scheme membership applications begin.

What the schemes assess

Unlike a financial regulator, the card schemes take a product-first approach to membership applications. They want to understand what the business does, how it will use scheme membership, and whether the risks it introduces are acceptable to the network. The application requires detailed documentation covering:

  • Business model and proposed programme design
  • Financial statements and capital adequacy
  • Compliance framework including AML, KYC and fraud controls
  • Technical infrastructure for card issuing and transaction processing
  • Settlement and liquidity capability
  • Governance and key personnel

Applications are not purely pass/fail assessments – they involve ongoing dialogue with the scheme’s membership team. Knowing how to position the application and how to respond to queries materially affects both the outcome and the timeline.

What to watch for

  • Scheme membership applications run in parallel to, not instead of, regulatory licensing. Both are required and both take time. Plan for a combined timeline of 18 to 36 months from a standing start.
  • The schemes have discretion in accepting members and can decline applications without detailed explanation. Prior scheme experience, a credible compliance track record, and a clearly defined programme are material to the outcome.
  • Mastercard and Visa have different fee structures and, to some degree, different programme requirements. Most European card issuers pursue both, but the applications are separate and the timelines may differ.

What does it cost to become a principal member?

Answer

Principal membership involves both one-time application and setup costs and ongoing annual fees. Total first-year costs for a UK or European project are typically in the low to mid six figures per scheme, with significant variation depending on programme type, geography, and whether the applicant is pursuing issuing, acquiring or both.

The cost components

Scheme costs for principal membership cover several categories. Application fees are payable at submission and are non-refundable regardless of outcome. BIN registration fees are paid when BINs are assigned. Ongoing membership fees are levied annually and are typically tiered by transaction volume. Settlement fees apply per transaction processed through the scheme’s network.

These are the direct scheme costs. The indirect costs – internal resource, technology build or integration, legal and compliance advisory, and the ongoing operational overhead of maintaining scheme compliance – typically exceed the direct scheme fees for most applicants.

Why Mastercard is generally less expensive than Visa in Europe

This is a well-documented pattern in the European market. Mastercard’s membership fee structure for European applicants is generally lower than Visa’s, particularly for issuers at lower transaction volumes. For businesses pursuing both, the gap in total first-year cost can be material. This difference narrows significantly at higher volumes where scheme incentive programmes and volume discounts become relevant.

What to watch for

  • Published fee information from the schemes is limited. Budget figures from advisers who have recently completed membership applications are more reliable than public estimates, which date quickly.
  • The cost of maintaining principal membership – ongoing fees, compliance resource, scheme audits, rule change implementation – often exceeds the initial setup cost within three to four years. Model the total cost of ownership, not just the entry cost.
  • For most fintechs at early or mid-scale, the economics of BIN sponsorship remain more favourable than principal membership until transaction volumes and programme complexity justify the overhead of direct membership.

Who holds settlement responsibility in each membership model?

Answer

In a principal membership model, the principal member settles directly with the card scheme – they hold the settlement account with the scheme and bear the liquidity and counterparty risk of settlement. In an affiliate model, settlement flows through the principal member: the scheme settles with the principal, who then settles with the affiliate. The affiliate does not have a direct settlement relationship with the scheme.

Why settlement responsibility matters operationally

Settlement timing, settlement currency, and the handling of failed settlements are all governed by the principal member in an affiliate arrangement. The affiliate’s settlement terms are set by the programme agreement with the principal – they are not directly negotiable with the scheme. This means the affiliate is exposed not only to its own settlement performance but to the principal’s financial standing and operational reliability.

This is one of the most significant risk factors in choosing a BIN sponsor. A principal member that encounters financial difficulty – even temporarily – can create settlement delays or failures that cascade to all affiliated programmes running under its BINs, regardless of the individual affiliate’s own financial health.

Settlement currencies and multi-market implications

Principal members settle in the currencies supported by their scheme membership and their settlement banking arrangements. For programmes operating across multiple European markets, the principal’s settlement currency coverage directly determines what currencies the affiliate programme can support without additional FX conversion steps. A principal member with settlement capability in EUR, GBP, PLN, HUF and RON – as DiPocket provides – enables multi-currency programmes without the affiliate needing separate banking arrangements for each currency.

What to watch for

  • Ask your prospective BIN sponsor for their settlement banking arrangements and which currencies they settle in directly. Settlement via FX conversion introduces additional cost and timing risk.
  • Ask about the sponsor’s financial standing and capital adequacy. As an affiliate you are operationally exposed to their financial health in the settlement chain even though they are not your bank.
  • Understand the settlement cycle your programme will operate on – T+1, T+2 or other – and how failures or disputes in the settlement chain are handled under the programme agreement.

Can an affiliate member sponsor other businesses to issue cards?

Answer

No. Only principal members can sponsor other businesses as affiliate or associate members of a card scheme. An affiliate member does not own BINs and cannot grant access to a BIN it does not hold. Sub-sponsorship arrangements – where an affiliate purports to sponsor a third party – are not permitted under Visa or Mastercard’s rules.

Why this matters when evaluating infrastructure partners

The practical implication is straightforward: if you are evaluating a provider who claims to offer BIN sponsorship, that provider must be a principal member of the relevant scheme. An affiliate or associate member cannot legitimately act as a BIN sponsor regardless of how the commercial arrangement is described.

This is not a technicality – it is a scheme rule violation that can result in the termination of all programmes running under the relevant BIN. Due diligence on a prospective sponsor should confirm their principal membership status directly with the scheme’s member directory, not just from the provider’s own documentation.

What to watch for

  • Verify principal membership status directly through Visa’s or Mastercard’s member directories. These are accessible to businesses evaluating scheme participants and are more reliable than self-reported membership claims.
  • Be cautious about arrangements described as ‘programme management’ or ‘card issuing facilitation’ without explicit confirmation of the underlying principal membership that makes card issuance possible.

What is the difference between affiliate and associate membership?

Answer

The terminology varies between Visa and Mastercard. Visa uses ‘affiliate member’ and Mastercard uses ‘associate member’ to describe the same structural position: a business that issues cards under a principal member’s BIN, with a scheme registration but without a direct scheme contract. For practical purposes, affiliate and associate membership in a card scheme context are the same thing.

Why the terminology is inconsistent

Visa and Mastercard developed their membership frameworks independently and use different terminology throughout their rules and documentation. This creates terminology confusion in commercial discussions, particularly in multi-scheme programmes where a business may be described as a Visa affiliate and a Mastercard associate simultaneously, despite holding structurally identical positions in each network.

Some advisers and providers use ‘associate member’ as a generic term covering any non-principal participant, including those with more limited access than a full affiliate. In scheme documentation, the specific capabilities and obligations attached to each membership tier are what matter – the label alone does not determine what a member can do.

 

Membership terminology across schemes at a glance

Position Visa terminology Mastercard terminology
Direct scheme member with BIN ownership Principal member Principal member
Sponsored member operating under a principal’s BIN Affiliate member Associate member
Programme manager without direct scheme registration Third party agent / TPP Third party processor / TPP

 

What to watch for

  • When reviewing a programme agreement or scheme documentation, do not assume the same term means the same thing across Visa and Mastercard materials. Check the specific capabilities and obligations defined for the membership tier in each scheme’s rules.

How does the principal member’s scheme membership affect the programmes built on top of it?

Answer

A principal member’s scheme membership scope – which schemes, which geographies, which card types – sets the ceiling for every affiliate programme running under it. An affiliate cannot operate in a market the principal is not authorised for, cannot issue on a scheme the principal is not a member of, and cannot access card products or programme features the principal has not enabled within their own membership.

Geographic reach

A principal member’s scheme membership is granted for specific geographies. In Europe, a principal member authorised in one EEA jurisdiction can typically passport their scheme membership across EEA markets, but this requires the regulatory authorisation to operate in those markets as well as the scheme membership itself. For an affiliate, the operational footprint is bounded by wherever the principal can legitimately operate.

This is why a principal member’s European footprint – not just their membership status – is a meaningful evaluation criterion. A sponsor with Visa and Mastercard principal membership but regulatory authorisation only in one jurisdiction cannot legitimately support a multi-market programme in the same way that a dual-regulated sponsor with established operations across 15 markets can.

Scheme and card product access

Not all principal members hold membership of both Visa and Mastercard. A principal that is a Visa member only cannot sponsor a Mastercard programme, and vice versa. For businesses that want the flexibility to issue on either scheme – or to run both Visa and Mastercard programmes simultaneously – dual membership of the sponsor is a prerequisite, not a preference.

Similarly, access to specific card product types – virtual cards, tokenised cards for mobile wallets, commercial card products, prepaid – depends on the principal member having those features enabled within their own membership. An affiliate cannot access programme features the principal has not activated.

What to watch for

  • Confirm your prospective sponsor holds principal membership of both Visa and Mastercard if you want programme flexibility or dual-scheme issuance. Single-scheme membership limits your options at launch and reduces leverage if commercial terms with one scheme change.
  • Ask specifically about tokenisation support (Apple Pay, Google Pay compatibility) – this requires the principal to have activated token service provider arrangements within their membership. It is not automatically available.
  • For multi-market programmes, ask the sponsor to confirm their regulatory authorisation on a market-by-market basis, not just their scheme membership. The two are independent requirements and gaps in either will prevent launch in that market.

When does it make sense to move from affiliate to principal membership?

Answer

Moving from affiliate to principal membership makes sense when the cost of ongoing BIN sponsorship fees exceeds the cost of running direct membership at your transaction volume, when you need programme features or geographies your current sponsor cannot provide, when your risk profile requires the independence of owning your own BINs, or when you want the ability to sponsor other businesses yourself.

The economics threshold

At sufficiently high transaction volumes, the per-transaction scheme fees paid through a BIN sponsor’s margin become more expensive than the direct scheme fees a principal member would pay. The crossover point varies by programme type, transaction mix and the sponsor’s fee structure, but for most European card programmes it falls somewhere in the range of several million transactions per year. Below that threshold, the overhead of principal membership – fee base, compliance resource, operational investment – is unlikely to be justified on economics alone.

The control and independence argument

Beyond economics, some businesses pursue principal membership for strategic reasons: full control over the scheme relationship, the ability to negotiate directly with Visa and Mastercard on programme terms, independence from a third party’s financial health in the settlement chain, and the credibility that direct membership confers in certain commercial contexts. These are legitimate reasons to pursue direct membership at a scale where the economics are marginal.

Planning the transition

Moving from affiliate to principal membership involves re-registering active card programmes with the scheme under the new principal’s BINs, which typically requires re-issuing physical cards to existing cardholders and updating card-on-file registrations. This is operationally significant and should be planned well in advance. A BIN sponsor who has helped clients through this transition – and who has an interest in supporting it rather than obstructing it – is a meaningfully better long-term partner than one who does not.

What to watch for

  • Model the full cost of principal membership before deciding it is economically justified – include compliance resource, technology investment, scheme audit costs and the ongoing operational overhead, not just direct scheme fees.
  • Discuss the transition pathway explicitly with your BIN sponsor before signing. A sponsor who actively supports and plans for eventual principal membership is a better long-term partner than one who treats it as a competitive threat.
  • The timeline from deciding to pursue principal membership to live operation is typically 18 to 36 months. Factor this into your programme roadmap if you are building toward eventual direct membership.

Evaluating your route to card scheme access? works?

DiPocket holds principal membership of both Visa and Mastercard and has supported fintechs, PSPs and non-financial businesses through every stage of the card programme journey – from affiliate launch to principal membership transition. Explore our BIN sponsorship service or read the full guide: BIN sponsorship explained.

What is the difference between a BIN sponsor and an issuer processor?

What is a BIN in payment card issuing

A BIN sponsor provides the regulatory and scheme infrastructure that makes card issuance legally possible: principal membership of a card scheme, a licensed BIN, and accountability to Visa or Mastercard for scheme compliance. An issuer processor provides the technology infrastructure that makes transactions work in real time: authorisation, clearing, settlement messaging, card lifecycle management, and spend control enforcement. The two roles are structurally distinct and governed by separate contractual relationships – but they are frequently provided by the same entity, which has significant implications for programme flexibility and negotiating leverage.

On this page:

What does a BIN sponsor do?

Answer

A BIN sponsor provides the regulatory and scheme-level infrastructure that makes card issuance possible. Specifically: they hold principal membership of a card scheme, own or control the BINs used by client programmes, register client programmes as affiliate members of the scheme, bear accountability to Visa or Mastercard for compliance across all cards issued under their BINs, and provide the settlement infrastructure through which card transactions are cleared and funds move.

The regulatory dimension

A BIN sponsor must hold a regulatory licence – typically an Electronic Money Institution (EMI) licence or banking licence – issued by a recognised financial regulator. In Europe, this is a prerequisite for principal scheme membership and for operating any card issuance activity. The sponsor is the regulated entity in the programme: it is accountable to the regulator and to the card scheme for the conduct of all cards issued under its BINs, regardless of how many client programmes are running beneath it.

This is not a passive role. The sponsor must maintain active oversight of the compliance standards of all affiliated programmes, approve programme design and marketing materials, and ensure that AML and KYC standards are met consistently across all clients. A sponsor that takes a light-touch approach to these obligations is a compliance risk for client programmes – not just for itself.

The scheme dimension

The BIN sponsor’s scheme membership determines what the client programme can access: which networks (Visa, Mastercard or both), which geographies, which card product types, and which programme features. The sponsor negotiates directly with the schemes on fees, programme parameters, and product access. Clients benefit from the sponsor’s commercial relationships with the schemes but do not have a direct voice in those negotiations.

What to watch for

  • Confirm the sponsor holds principal membership – not affiliate membership – of the relevant scheme. Only principal members can legitimately sponsor client programmes.
  • Ask specifically about the sponsor’s oversight model: how do they monitor the compliance of client programmes on an ongoing basis? A sponsor with weak oversight processes creates scheme compliance exposure for all programmes under its BINs.

What does an issuer processor do?

Answer

An issuer processor provides the transaction technology infrastructure that connects the card programme to the scheme network and handles the real-time mechanics of every card transaction. This includes authorisation processing, clearing and settlement messaging, card lifecycle management (issuance, activation, blocking, replacement), spend control enforcement, and the data feeds that drive programme reporting and reconciliation.

The authorisation function

When a cardholder presents a card, the transaction request arrives at the issuer processor’s authorisation platform within milliseconds. The platform applies the programme’s configured rules – spend controls, fraud logic, account status checks – and returns an approval or decline to the card scheme’s network before the cardholder’s card reader has finished processing. The speed, reliability and configurability of this function directly determines the cardholder experience and the programme’s operational performance.

Card lifecycle and scheme connectivity

Beyond real-time authorisation, the issuer processor manages the full card lifecycle: issuing card numbers and PINs, managing tokenisation for mobile wallets (Apple Pay, Google Pay), processing card replacements and blocks, and handling dispute and chargeback workflows in line with scheme rules. They also maintain the technical connectivity to the scheme’s network infrastructure and are responsible for implementing scheme rule changes and technical updates as they are released by Visa and Mastercard.

Key European issuer processors

The European issuer processing market is served by a relatively small number of specialist providers. Thredd (formerly GPS) is one of the largest and most widely used. Others operating in this space include Marqeta, Nuvei, and various providers that have expanded into processing from adjacent positions in the payments stack. The processor a programme runs on matters commercially as well as technically – fee structures, transaction volume thresholds, and product capability vary materially between providers.

What to watch for

  • Processor capability is programme-specific, not generic. A processor that works well for a high-volume consumer prepaid programme may not be the right fit for a low-volume B2B virtual card programme with complex spend control requirements. Evaluate fit for your specific use case.
  • Ask about the processor’s scheme certification status. Processors must be certified by Visa and Mastercard to process on their networks, and certifications have scope limits. Confirm the processor is certified for the card types and geographies your programme requires.

Who is accountable for regulatory compliance in a card programme?

Answer

The BIN sponsor – as the regulated entity and scheme principal member – holds ultimate accountability for regulatory compliance in a card programme. The issuer processor operates a compliant technical environment (PCI DSS, scheme technical rules) but regulatory accountability under frameworks such as PSD2 and AML legislation rests with the licensed entity, which is the sponsor.

The compliance division in practice

The regulatory compliance picture in a card programme involves three overlapping layers, and the distinction between them matters:

  • Scheme compliance – adherence to Visa and Mastercard’s operating rules. Accountability sits with the principal member (the BIN sponsor). The processor supports this by implementing scheme rule updates in their technical platform, but the sponsor is accountable to the scheme.
  • Regulatory compliance – adherence to financial regulation (PSD2, AML Directives, data protection). Accountability sits with the licensed entity – again the sponsor, as the EMI or bank. The processor is not regulated as a financial institution and does not carry this accountability.
  • Technical compliance – PCI DSS and scheme technical standards for data security and transaction processing. This is primarily the processor’s domain: they operate the environment in which card data is handled and are responsible for maintaining the certifications that cover that environment.

A card programme therefore has two separately accountable compliance parties: the sponsor for regulatory and scheme-rule accountability, and the processor for technical security compliance. This distinction matters when reviewing programme agreements – the allocation of compliance obligations, indemnities, and incident response responsibilities should reflect this division explicitly.

What to watch for

  • Do not assume that because a processor operates a PCI DSS-certified environment, the programme is fully covered from a regulatory compliance standpoint. PCI DSS is a data security standard, not a regulatory compliance framework.
  • In the programme agreement with your BIN sponsor, check how compliance obligations are allocated between the sponsor, the processor and your own business. Ambiguity in this allocation creates risk that will only become visible when something goes wrong.

What happens when one provider offers both roles?

Answer

When a single provider acts as both BIN sponsor and issuer processor – often described as a fully integrated or turnkey card programme platform – the client has one commercial relationship, one contract, and one point of accountability. This simplifies launch and reduces integration complexity. The trade-off is reduced flexibility: switching either the sponsor or the processor relationship means switching both, because they are contractually and technically bundled.

The case for integrated providers

For most businesses launching their first card programme, an integrated provider offering both BIN sponsorship and issuer processing is a sensible starting point. The integration between the two functions is already built, scheme and regulatory compliance is coordinated by one team, and time to market is faster than assembling separate relationships. The operational burden of managing two vendor relationships is also reduced.

DiPocket provides both BIN sponsorship and processing infrastructure, working with multiple issuer processors – including Thredd – to give clients flexibility in their processing arrangement while maintaining a single point of accountability for scheme compliance and regulatory oversight.

The processor flexibility question

The critical question with any integrated provider is not whether they bundle both roles, but whether their processing arrangement is fixed or flexible. Some integrated providers are tied to a single processor: the BIN sponsorship and the processing are offered as a single indivisible product, and the client has no ability to use a different processor. Others, like DiPocket, operate with multiple processors and allow the processing component to be selected or changed based on the client’s requirements.

Processor lock-in has operational consequences that only become visible as a programme grows. If the bundled processor cannot support a new geography, a higher transaction volume, or a specific technical requirement, the client has no recourse short of migrating the entire programme to a new provider – including re-issuing cards to existing cardholders.

What to watch for

  • When evaluating an integrated provider, ask explicitly: are the BIN sponsorship and processing components separable? Can you change the processor without changing the BIN sponsor? The answer to these questions determines your long-term flexibility.
  • Ask which processors the sponsor works with and whether you can specify or influence the choice. A sponsor who works with multiple processors and is transparent about the options is materially better positioned to support a growing programme than one who cannot answer the question.

What is a programme manager, and how does it relate to these two roles?

Answer

A programme manager is an entity that takes operational responsibility for running a card programme on behalf of the client – coordinating between the BIN sponsor, the issuer processor, the card bureau, and other service providers. A programme manager does not need to hold a regulatory licence or scheme membership themselves. They act as the operational layer above the infrastructure, not as part of it.

Where the programme manager sits

In a card programme with all roles separated, the structure typically looks like this: the BIN sponsor provides regulatory and scheme access; the issuer processor handles transaction technology; and the programme manager coordinates the operational delivery – onboarding, card management, dispute handling, reporting, and day-to-day scheme rule compliance on behalf of the client. The client sits above all of these.

In an integrated provider model, the sponsor often also acts as the programme manager, handling operational coordination as part of the service. This is the model DiPocket operates: the BIN sponsorship, operational oversight, and programme support functions are provided by the same entity.

Why the distinction matters

Some providers in the market describe themselves as programme managers or card programme platforms without being the BIN sponsor themselves – they are sitting above a sponsor and a processor without holding the scheme membership or regulatory licence that underpins the whole arrangement. This creates a longer chain of dependency and an additional potential failure point. If the provider’s relationship with the underlying sponsor breaks down, every programme running on the platform is affected.

What to watch for

  • If a provider describes themselves as a programme manager, ask directly: who is the BIN sponsor, and do they hold principal scheme membership? The answer tells you where the regulatory and scheme accountability actually sits.
  • The longer the chain between your programme and the regulated entity, the more dependency risk you carry. Ideally the BIN sponsor, the regulatory licence holder, and the scheme principal member are the same entity.

Can you switch issuer processor without changing BIN sponsor?

Answer

In principle yes, but in practice it depends entirely on the contractual and technical architecture of your current arrangement. If the BIN sponsor and issuer processor are separate providers with separate agreements, processor migration is technically possible without changing the sponsor relationship. If the two are contractually bundled, changing the processor means changing the sponsor – and everything that entails.

What processor migration actually involves

Even where processor and sponsor relationships are technically separable, migrating an issuer processor is a significant technical project. The new processor needs to be integrated with the sponsor’s settlement infrastructure, scheme registrations need to be updated to reflect the new processor, and the card programme’s transaction processing logic needs to be re-implemented and tested on the new platform. Active cardholders are typically not affected – card numbers and PANs do not change when a processor changes, because the PAN is associated with the BIN and the account, not with the processor.

When processor migration is worth considering

Processor migration becomes relevant when the current processor cannot support a new requirement – a new geography, a higher transaction volume tier, a specific spend control feature, or better pricing at scale. It is also relevant when a programme migrates to a new BIN sponsor who uses a different processor. In either case, the commercial benefits need to outweigh the migration cost and operational disruption, which is non-trivial for active programmes.

What to watch for

  • Before signing with any BIN sponsor, confirm in writing whether you have the contractual right to change issuer processor independently of the sponsor relationship. If the agreement is silent or ambiguous on this point, assume it is not permitted.
  • Processor migration for an active programme with cardholders takes months, not weeks. If your programme is growing and you anticipate needing to change processor, plan the migration well before the need becomes urgent.

Can you switch BIN sponsor without changing issuer processor?

Answer

Switching BIN sponsor is operationally more disruptive than switching issuer processor. A sponsor change typically requires re-registration of the programme with the card scheme under the new sponsor’s BINs, which means issuing new card numbers to existing cardholders – because the BIN prefix changes. This is the most operationally significant aspect of any programme migration.

What a sponsor migration actually involves

When a programme moves to a new BIN sponsor, the cards in existing cardholders’ hands carry the old sponsor’s BIN. Those cards cannot simply be reassigned to a new BIN – the card number incorporates the BIN prefix and cannot be changed without physical or virtual card replacement. This means all active cardholders need to be re-issued new cards, all card-on-file registrations (subscriptions, saved payment methods) need to be updated, and the programme needs to operate on both old and new BINs simultaneously during a transition period.

This is the most frequently cited reason why businesses stay with a sub-optimal BIN sponsor longer than they should – the cost and complexity of migration is significant, and underestimated at the time the original sponsor relationship was established.

Whether the existing processor can be retained

In some cases, the new BIN sponsor will work with the same issuer processor as the old one, allowing the programme to migrate the sponsor relationship without also migrating the processing infrastructure. Whether this is possible depends on the new sponsor’s processing relationships and the technical architecture of the existing programme. Where it is possible, it materially reduces migration complexity.

What to watch for

  • When selecting a BIN sponsor, think explicitly about the migration scenario. How would you exit this relationship if needed, and what would the cardholder impact be? A sponsor who has managed client migrations – and who can describe how they approach them – understands the risk they are asking you to accept.
  • Build a cardholder re-issuance cost estimate into any programme migration business case. For programmes with tens of thousands of active cardholders, card replacement logistics alone represent a material cost and operational project.

What should you ask when evaluating a provider that bundles both roles?

Answer

The core questions to ask a provider that offers both BIN sponsorship and issuer processing are: whether the two components are contractually separable, which processors they work with and whether you can specify or change the processor, what their authorisation performance and uptime data looks like, how they handle a client that needs to migrate to a different processor or direct scheme membership, and what their financial standing and regulatory compliance track record is.

The separation question

Ask directly: if I need to change processors in two years because my volume has grown or my requirements have changed, can I do that without changing BIN sponsor? A provider who cannot answer this question clearly, or who answers it with a commercial deflection rather than a structural explanation, is signalling that the two components are effectively locked together.

Performance and stability

For the processing component, ask for authorisation uptime SLA data and historical authorisation rate performance across programmes comparable to yours. Uptime SLAs below 99.9% for the authorisation platform are a concern for any programme where card acceptance reliability matters to the cardholder experience. Authorisation rate performance tells you how effectively the platform converts legitimate transaction attempts into approvals.

For the sponsorship component, ask about the provider’s financial standing, regulatory audit history, and how they have handled compliance incidents or scheme rule changes across their client portfolio. A sponsor who has been operating for a decade and has navigated multiple regulatory changes is materially more credible than one who cannot speak to their history.

BIN sponsor vs issuer processor: roles at a glance

 

Dimension BIN sponsor Issuer processor
Primary function Regulatory and scheme access Transaction technology
Licence required EMI or banking licence Scheme processor certification
Scheme relationship Principal member – direct Certified processor – technical
BIN ownership Yes – owns or controls BINs No – operates within sponsor’s BINs
Settlement accountability Yes – settles with scheme No – supports settlement data
Regulatory accountability Yes – PSD2, AML, scheme rules No – technical standards only (PCI DSS)
Real-time authorisation No (unless also the processor) Yes – core function
Spend controls Defines permitted parameters Enforces in real time
Can be changed independently Only if not contractually bundled Only if not contractually bundled

 

What to watch for

  • Ask for the provider’s authorisation uptime SLA in writing, and ask for historical performance data. Claims of high uptime without supporting data should not be taken on trust for a function this operationally critical.
  • Ask how the provider has handled clients that outgrew the bundled arrangement and needed to move to direct scheme membership or a different processor. Their answer tells you whether they see themselves as a long-term partner or a fixed-term infrastructure contract.

Questions about how DiPocket’s BIN sponsorship and processing infrastructure works?

DiPocket provides BIN sponsorship with processor flexibility – working with multiple issuer processors including Thredd so that clients are not locked into a single processing arrangement as their programme grows. Explore our BIN sponsorship service.