Regulatory sandboxes for financial infrastructure and the SUPA Protocol experience

From the UK and Spain to South Korea and Saudi Arabia, regulatory sandboxes offer very different routes to market. Drawing on SUPA Protocol’s applications and regulator enquiries, I compare what each programme provides, where the limits lie and what it takes to turn a prototype into a viable pilot.

Regulatory sandboxes for financial infrastructure and the SUPA Protocol experience

When I started preparing SUPA Protocol’s regulatory sandbox applications, I expected to find several versions of the same process: describe the innovation, agree the limits, run a test and establish a clear route to market. Working through the forms and engaging with regulators revealed just how different the mechanisms behind the terms sandbox, innovation hub and fintech concierge can be.

Some authorities have tools for a limited live test. Others help explain the requirements but leave the legal classification of the model to the applicant and its advisers. Some select projects around a particular theme. Separately, central banks run infrastructure experiments where a founder needs to propose a useful use case to an established group of participants.

In this article, I compare eight jurisdictions where we have worked on applications and enquiries: the UK, Guernsey, Spain, Ireland, the Netherlands, South Korea, Bahrain and Saudi Arabia. I also consider nine further markets from our research, alongside several infrastructure initiatives. The official requirements are described as at the date of this article; assessments of their suitability for SUPA are my own.

My main criterion is how well a programme helps us agree a lawful, testable and financially viable pilot. A quick email response is useful, but its value depends on the decision we can make as a result.

Why a financial protocol is difficult to describe in a standard application

We are developing SUPA Protocol as infrastructure for financial institutions to work together: maintaining consistent records and reconciling them, with coordination of payment instructions and settlement positions planned for later stages. The current prototype can demonstrate participant creation, a proprietary ledger — a system of accounting records — and reconciliation. Live interbank settlement and legally effective netting form part of the proposed development and testing.

Under the proposed model, funds will remain with the banks and financial institutions participating in the pilot. We still need to establish exactly what the protocol operator does, which decisions remain with participants and when a record in the system has legal consequences.

One application may simply pass data to a bank. Another may initiate payments independently. A third may set the rules for admitting participants and discharging obligations. The interfaces can look similar to a user, while the allocation of authority and responsibility differs substantially.

Even the absence of custody of customer funds does not settle the regulatory question. For example, the Irish provision for technical service providers specifically excludes payment initiation and account information services from its scope. We therefore need to examine the individual functions, rather than infer the legal position from a single feature. S.I. No. 6/2018, Regulation 4(1)(j).

For SUPA, this raises several connected questions. When does our work remain the provision of software? Which functions amount to a payment service? What obligations arise if we govern the network’s rules? Can calculated positions be used to discharge obligations, and what happens if a participant suffers a failure or becomes insolvent?

Netting — offsetting obligations against one another — is a separate issue. Reducing several payments to a single net amount is relatively straightforward arithmetic. For the result to be legally effective between institutions, it needs contractual rules, applicable law, a process for recognising obligations and default scenarios. These are the questions that turn a technology demonstration into an infrastructure experiment.

Which mechanisms are worth comparing

I group programmes by the outcome they can offer a founder. This is an analytical classification: official programme names can overlap.

Mechanism

Practical outcome

What to establish before taking part

Sandbox permitting a limited test

Conditions for conducting a particular experiment

The legal basis for the test and the functions permitted

Innovation hub or contact point

Preliminary dialogue about requirements and the relevant authorities

How specific the guidance can be and who makes the next decision

Thematic programme

Work with the regulator on a selected problem

Whether the project fits the theme and whether live operations are permitted

Infrastructure pilot

Testing a use case on particular settlement infrastructure

Requirements for the operator, participants, technology and connectivity

Commercial accelerator

Finding partners, developing the product and building sales

What outcomes are available beyond meetings and presentations

Successful participation in an accelerator can help find a bank. A productive meeting with a hub can clarify the model. A limited test can gather evidence. Each subsequent transition, however, requires its own decision: from enquiry to admission, from admission to launch, and from an experiment to ongoing operations.

This sequence also matters when describing progress publicly. As at the date of this article, our Spanish application has been registered in the electronic system, and we have corresponded with Ireland’s Innovation Hub. Confirmation of submission establishes that an application has been made. Admission and testing conditions are considered separately.

Our applications and enquiries across eight jurisdictions

The table summarises the main differences between the channels. The final column reflects my assessment of their possible role for SUPA, rather than a commitment from the regulator.

Jurisdiction

Mechanism

Possible role for SUPA

UK

FCA Regulatory Sandbox

Agreeing a limited live test and the necessary permissions

Guernsey

GFSC Innovation Sandbox and Concierge

Discussing the appropriate regime and licensing conditions

Spain

Espacio Controlado de Pruebas under Ley 7/2020

Testing a sufficiently mature prototype under an agreed testing protocol

Ireland

Innovation Hub and a separate thematic Sandbox Programme

Preliminary dialogue; structured engagement with the regulator where a suitable cohort is available

Netherlands

Joint DNB, AFM and ACM InnovationHub

Clarifying the classification of functions and allocation of supervisory responsibilities

South Korea

Designation as an Innovative Financial Service

Specific regulatory exemptions for an eligible project serving the local market

Bahrain

CBB Regulatory Sandbox

A pilot with defined participants, risks, limits and an exit plan

Saudi Arabia

SAMA Regulatory Sandbox

Preparation in stages, followed by live testing once readiness conditions are met

I examine the official basis and limitations of each mechanism below.

UK

The FCA accepts Regulatory Sandbox applications throughout the year. The programme allows testing with real users and includes technology firms helping regulated institutions meet their obligations. Its tools include restricted authorisation, individual guidance and, where applicable, waivers or modifications of the FCA’s own rules. Statutory requirements and the need for appropriate permission to carry out regulated activities remain in place. FCA Regulatory Sandbox.

For an infrastructure start-up, I find the opportunity to agree the scope of a test particularly useful: who participates, which operations are permitted, what we measure and what must be ready before launch. That discussion connects the product’s architecture with the actual allocation of responsibility.

The application also needs to explain why the project needs the sandbox. Uncertainty over the network’s functions, testing safe interaction between participants or a need for restricted permission are concrete reasons. Obtaining a recognisable logo or accelerating the search for investors is a much weaker rationale; the FCA explicitly describes the limits of its support and the absence of endorsement. FCA application guide.

The UK route requires a separate understanding of the respective roles of the FCA and the Bank of England. Payment services, oversight of a system and access to settlement may involve different authorities and procedures. For SUPA, I see the first pilot as a way to demonstrate that the processes can be controlled and to clarify the operator’s functions. The question of fully developed settlement infrastructure should follow from the results and the chosen model.

The corporate structure also depends on that choice. For example, the standard payment institution authorisation route requires a UK body corporate with its head office and registered office in the UK. The rules for incorporating an ordinary company do not, by themselves, describe the requirements for a future financial operator. FCA, Authorised payment institutions.

Guernsey

The GFSC describes its Innovation Sandbox as a mechanism operating within existing legislation, with tailored licensing conditions. Activities may be restricted, followed by a transition to a different set of permissions or an orderly end to the test. The programme does not create a universal, standalone sandbox licence or replace legal advice. GFSC Sandbox FAQs.

I see Guernsey’s appeal in the opportunity to discuss the model with the regulator before fully establishing the business. For a project combining several infrastructure functions, it is useful to have a channel through which to explore the appropriate regime and the practical presence required on the island.

The requirement for two principal officers stood out in our early research. Precision matters here: on its general page for new applicants, the GFSC refers to the majority of cases and to experienced officers with executive powers who are physically present in the Bailiwick. How that requirement applies to a particular project needs to be clarified in the context of its activities. GFSC New Applicants.

For a founder, this could be a significant cost. If the model requires local management and a qualified team, the nominal cost of incorporation becomes a small part of the budget. I would therefore assess Guernsey against the agreed requirements for the operator and the prospects of finding pilot participants.

A licence with conditions in one jurisdiction also does not automatically resolve the requirements for working with banks elsewhere. For SUPA, a local experiment is valuable if its results can be explained to subsequent partners and regulators: which risks have been tested, which obligations have been established and which elements require further agreement.

Spain

Spain’s regime is particularly interesting for institutional infrastructure. Ley 7/2020 includes greater efficiency for institutions or markets, improved compliance and better financial supervision among its criteria for technological innovation. It allows a prototype with minimum useful functionality and provides for an agreed testing protocol. That protocol sets out the stages, volumes, participants and resources; specified protections and financial guarantees covering liability must be in place before testing begins. Ley 7/2020, Articles 5, 8, 9 and 13.

For SUPA, this gives us a clear basis for describing the potential benefits: more consistent records, reproducible reconciliation and a verifiable coordination process. Each expected benefit still needs to become a measurable hypothesis. Until the pilot has been conducted, lower costs and faster settlement remain research objectives.

On 29 September 2026, we registered an application for SUPA Protocol under the Banco de España category. This is a confirmed stage in our process; the subsequent decision will concern the assessment of the project and possible participation conditions. The twelfth application window runs from 1 September to 13 October 2026. Official information on the application round.

In practical terms, submitting the application made us produce a coherent account of which functions can already be demonstrated, which are proposed for testing, where the funds remain, what happens if something goes wrong and how the experiment ends. That work is useful in itself: it makes the gap between an investment presentation and a detailed testing plan much clearer.

For me, the strength of Spain’s approach is the opportunity to agree the conditions for a specific experiment around a sufficiently mature development. The challenge lies in the quality of preparation: we will need to substantiate participant protection, partner roles and the feasibility of the test. The agreed protocol will matter more than the idea’s initial appeal.

Ireland

Our enquiry to Ireland’s Innovation Hub showed how important it is to check expectations in advance. We wanted to discuss the boundary between a technical protocol and regulated financial infrastructure. The response directed us to published requirements and recommended obtaining a legal assessment of the specific model. Preliminary comments on the possible status of the activities came with the qualification that this analysis was needed.

From a founder’s perspective, the response can feel insufficiently specific: the product has already been described, yet the central uncertainty remains. However, the Hub’s stated remit excludes legal advice and statutory interpretation for an individual company. It explains frameworks and processes, considers innovation issues and helps direct enquiries to the relevant functions within the Central Bank. CBI, Engaging with the Innovation Hub.

My conclusion from that exchange is that it is better to arrive with a working legal hypothesis and a precise point of uncertainty. For example: if the operator calculates positions but has no authority over funds, which additional functions would change the classification, and which department should be involved in agreeing an experiment? That allows the architecture and the parties’ powers to be discussed systematically.

Separately, the CBI runs a six-month thematic Innovation Sandbox Programme. The 2026 cohort focuses on payments, and overseas applicants intending to serve the Irish market are eligible. However, the programme expressly provides no regulatory derogations or waivers for testing with consumers, and it does not find partners for participants. The page checked for this article shows applications for that cohort as closed. CBI Innovation in Payments.

An ordinary enquiry to the Hub and participation in the thematic programme therefore offer different levels of engagement. I think founders should understand that distinction before filling in the form. A regulator can have a useful programme even if the first email does not resolve an individual legal question.

Netherlands

The Dutch InnovationHub brings together DNB, AFM and ACM. It considers questions about innovation and supervision, but expressly states that its guidance creates no rights and does not allow statutory requirements to be bypassed. The website gives a target response time of ten working days. DNB InnovationHub.

For SUPA, the interest extends beyond the contact channel. DNB has a separate regime for certain payment processing service providers, associated with the concept of an afwikkelonderneming. Relevant organisations with their registered office in the Netherlands must notify DNB; licensing is linked to a threshold of more than 120 million specified non-cash transactions in the Netherlands during the preceding calendar year. DNB, Notification and licensing requirements.

This gives us a basis for asking a specific question about the classification of our functions. It does not yet establish that SUPA falls within that regime. Nor should the threshold be read as general permission for any financial network to operate freely below a particular scale: the activity and the applicability of the provision must be established first.

My assessment of the Netherlands therefore centres on the value of a discussion about classification. If the regulator helps distinguish software processing, a payment service and the operation of financial infrastructure, we can choose the next route based on what the operations actually involve.

Useful material for that discussion includes a diagram of information and money flows, contractual roles, authority over each instruction and an explanation of the legal effect of records. Terms such as “global network” and “bank-grade ledger” convey much less than an answer to who can change a participant’s final position, and on what basis.

South Korea

South Korea’s regime stands out because legislation provides for designation: recognising a particular service as innovative and granting specified regulatory exemptions. The initial designation can last up to two years, with extensions available under the law. Applicants need to identify which provisions prevent the service from being implemented and how users will be protected. Special Act on Support for Financial Innovation.

For an infrastructure project, this is potentially useful: a specific obstacle can be identified and a limited experiment proposed. The applicant’s own eligibility must be established first, however. Article 5 ties eligibility to specified categories of financial company or a company under Korea’s Commercial Act with a place of business in the country; the law also considers whether the service is directed towards the domestic financial market. An overseas applicant needs to establish which eligibility basis applies. The Act, Articles 5 and 13, official FAQs.

The office address is therefore secondary to the question of legal status. Renting a desk can support genuine operational activity, but does not in itself establish that a company meets the admission requirements. For a founder, this is a significant preparation risk: a compelling technology description cannot remedy an ineligible applicant.

The third application round of 2026 ran from 14 to 30 September and had closed by the date of this article. The next deadline should be checked against a new announcement. Financial Regulatory Sandbox portal.

My assessment of South Korea is that it offers a strong tool for a project with a clearly identified legal issue, an established basis for local eligibility and a clear benefit to the market. For SUPA, preparing the legal model and finding an institutional participant able to explain why the test is needed are particularly important.

Bahrain

When preparing the CBB form, I was struck by its practical focus. Applicants need to describe the workflow, onboarding and KYC, partners, volunteer participants, transaction volumes, confidentiality, risks, communications and success measures. The form allows no more than 100 volunteer customers; its declaration specifies the use of a CBB-licensed retail bank when handling participants’ funds. CBB Regulatory Sandbox Application Form.

For our model, this provides a useful way to explore responsibility. If funds remain with the bank, who confirms that a transaction can proceed? How does the protocol learn that it has actually been executed? How is a discrepancy detected? Who informs the participant and who corrects the records?

These questions help make a pilot workable. They also show why the statement “we do not hold funds” needs more explanation: a service outage, data breach or incorrectly calculated position can cause harm even when funds never pass to the protocol operator.

The CBB updated its framework in December 2021, introducing a more consistent approach in stages. Older timelines and parameters from material about the original launch should therefore be checked before they are used in a current plan. CBB Annual Report 2021.

For SUPA, I see the value of Bahrain in the opportunity to agree a specific local pilot. At the preparation stage, we did not yet have an agreement with a participating bank. That is a practical dependency: being able to complete the form does not provide access to banking operations.

Saudi Arabia

SAMA expressly provides a route for international applicants: applying directly and then meeting the requirements to establish a local entity following acceptance, or participating through a licensed Saudi partner. These options allow discussions about the project to begin before the corporate structure is finally chosen. SAMA, Who Can Apply.

The process is divided into application assessment, operational readiness, testing and exit. The guidance gives an assessment target of 60 working days; up to 120 days are available for preparation following a preliminary positive decision, and live testing lasts 6–12 months. Readiness conditions must be met before permission for live testing is granted. SAMA Regulatory Sandbox Guidance.

For a founder, that distinction is useful. An idea can receive a positive assessment while the business is still not ready to run operations. The team, funding, contracts, security, reporting and controls over the agreed limits still need to be put in place. In our preparations, finding a Saudi institutional partner and completing an external integration remained future stages.

SAMA also links the need for a sandbox to genuine innovation and regulatory uncertainty. If a model already fits an existing regime, a logical outcome may be referral to the ordinary licensing process. SAMA guidance.

My conclusion is that the application should show which question an experiment can answer. For SUPA, that could be the allocation of responsibility when institutions agree positions, the testing of limits and the safe completion of operations. A general reference to digitalising the economy is much less persuasive than a testing scenario with a specific outcome.

Other markets in our research

The following nine jurisdictions broaden the comparison; their inclusion does not indicate that we have been admitted to their programmes. Each raises its own question: what support is actually available today, and does it suit the project’s stage of development?

Jurisdiction

What the channel offers

My assessment for an infrastructure project

Japan

The Payment Innovation Project within the FinTech PoC Hub, launched on 7 November 2025. FSA

Of interest for a specific payments experiment benefiting the Japanese market

Norway

The sandbox also admits technology providers serving supervised institutions. Licensing requirements remain in place. Finanstilsynet

A useful discussion for an infrastructure provider with an interested institution

France

The ACPR’s Pôle Fintech Innovation supports engagement on innovation issues and contact with the relevant departments. ACPR

Useful for discussing classification and authorisation; permission to test must be explored separately

Luxembourg

The CSSF Innovation Hub offers preliminary regulatory dialogue and assessment of models. CSSF

Makes sense with a clear local use case and a partner

Belgium

The joint NBB and FSMA FinTech Contact Point assists with regulatory questions. FSMA

An opportunity to discuss the model with two supervisory authorities

Italy

The latest application window published on the sandbox page remains 3 November to 5 December 2023. Banca d’Italia

Current application availability needs checking, and the sandbox must be distinguished from other programmes

Lithuania

The Bank of Lithuania’s sandbox assesses maturity, innovation and development of the service in the local market. Bank of Lithuania

Requires a substantive case for its use in Lithuania

Denmark

FT Lab allows up to five companies at a time and tests lasting up to six months, subject to applicable permission requirements. DFSA

A possibility for a tightly defined use case; availability must be confirmed

Hong Kong

EnsembleTX develops live experiments involving tokenised deposits and interbank settlement. HKMA

Potentially suitable if the future architecture and specific use case relate to that infrastructure

The table does not support a single ranking of countries. The same route may work well for a licensed bank and poorly for an independent developer without institutional participants.

Japan deserves particular attention. Through the Payment Innovation Project, the FSA describes support for specific payment initiatives, assessing project clarity, public benefit, innovation, user protection and resources. The first announced example was a joint stablecoin project involving major banks and Progmat. This indicates a focus on substantive experiments with a defined group of participants. FSA, PIP announcement, FSA, announcement of the first project.

For SUPA, my interest lies in the opportunity to discuss a testable payments hypothesis. We would still need to explain why Japanese institutions need it, how responsibility would be allocated and how applicable requirements would be met. The size of the market and its technological reputation do not resolve those questions.

Hong Kong’s EnsembleTX offers a different entry point. The HKMA announced it in November 2025 as a phase involving real-value transactions with tokenised deposits; initial settlement relies on HKD RTGS. Its areas of focus include liquidity and treasury management. Official HKMA announcement.

This is close to some of SUPA’s future research questions, but a proprietary ledger does not automatically imply DLT or tokenised deposits. We would first need to demonstrate a suitable use case, technical compatibility and the banks’ roles. I see that route as a separate infrastructure project requiring its own preparation.

I have revised several initial assessments in the European part of our research. The date of the most recent news item is not enough to declare a programme “dormant”. For Denmark, current intake and the ability to agree a test need checking; for Lithuania, the applicability of the criteria does. Restricted PI or EMI regimes should be analysed separately from sandbox admission rules.

Italy shows why programme names matter. While the latest application window published on the regulatory sandbox page remains the 2023 round, Banca d’Italia announced a fourth Milano Hub call in September 2026. These are different tools offering different outcomes for participants. Regulatory Sandbox, Milano Hub.

I would assess France, Luxembourg and Belgium through the quality of preliminary dialogue and the availability of partners. A contact point can be more useful than an internationally recognised sandbox if its response identifies the relevant authority and the next formal step. The quality of that support will only become clear through a specific enquiry; the programme’s name does not guarantee it.

What an infrastructure pilot needs to demonstrate

To move beyond promises, it helps to work through a simple hypothetical example. Suppose three institutions have obligations to one another in a single currency: A owes B 100 units, B owes C 80, and C owes A 70. The total value of the original obligations is 250 units.

Institution

Amount owed under the original obligations

Amount receivable

Net position

A

100

70

Pays 30

B

80

100

Receives 20

C

70

80

Receives 10

Under a suitable contractual model, the net result could be settled through a payment of 20 from A to B and 10 from A to C. This is only an illustration of the arithmetic, however. Whether those payments can replace the original obligations depends on the agreed rules and their legal effect. The parties also need to decide what happens if one institution cannot meet its obligation.

The example explains why a sandbox may be needed. Accounting software can display final positions in its own testing environment. Using those results between independent institutions requires checks on the data, authority, limits, agreement process, point of final settlement and response to errors.

For SUPA, I think a staged approach is sensible. First, demonstrate the functioning modules and test with synthetic data. Then conduct integration tests with participants. Live operations should follow once the applicable conditions have been agreed and all parties have demonstrated readiness.

Success measures must also fit the stage. The time taken to process a record measures software performance. The proportion of transactions reconciled automatically measures reconciliation quality. The funding actually required measures the economic effect of a particular scenario. These cannot be combined into a single promise of “faster settlement”.

Useful pilot results would cover the frequency of discrepancies, time taken to resolve them, recovery after a failure, completeness of the audit trail, compliance with limits and participants’ understanding of their obligations. Comparison with the existing process would help assess the benefits, while failure scenarios would establish the limits of safe use.

Access to central bank money

The prospect of access to settlement infrastructure stood out in our research. It requires a careful distinction between legal status, admission to a system and technical connectivity.

The ECB announced the launch of Pontes on 21 September 2026. The solution connects DLT platforms to TARGET for settlement in central bank money. The official page lists payment systems in the EU or EEA that are subject to oversight among the potential categories of operator, alongside other specified infrastructures. Market participants must meet the requirements for access to T2. ECB announcement, Pontes eligibility requirements.

For SUPA, this is a promising area for further study if the future model genuinely meets the technology and participation criteria. A proprietary ledger or incorporation in an EU country does not establish that eligibility. The operator, legal regime and network functions need to be defined before the connectivity requirements can be assessed.

The UK model of omnibus accounts in RTGS is also of interest for future payments infrastructure. Bank of England policy allows recognised payment system operators to apply and sets specific requirements, including CHAPS participation for funding and defunding. Recognition of the system and the decision on RTGS access are separate matters. BoE RTGS Access Policy, BoE Onboarding New FMIs.

The practical implication when choosing a jurisdiction is that we need to understand which authority will discuss the initial experimental function and which will assess the infrastructure as it grows. Building an early pilot budget around an assumption of future access to a central bank would be premature.

A sandbox can provide evidence about the model’s safety and design. Subsequent decisions will also depend on scale, governance, financial resilience, legal certainty and compatibility with the relevant infrastructure.

Assessing innovation alongside major industry projects

An infrastructure start-up needs to understand which problems central banks and established networks are already exploring. The BIS Project Agorá brings together work on programmable cross-border wholesale payments. In July 2026, the project conducted real-value testing; the BIS nevertheless describes the result as a prototype requiring further work. BIS Project Agorá.

In July 2026, Swift announced that its blockchain ledger was ready for initial use and that it was preparing a pilot with 17 banks for tokenised cross-border payments. Official Swift announcement.

These initiatives raise the bar for claims of innovation. SUPA needs to demonstrate a specific difference in the proposed model: the conditions for institutions to connect, the way records are agreed, the allocation of control, implementation costs or compatibility with existing processes.

That difference will still need to be tested. Even with a convincing architecture, the regulator and prospective customer need evidence from defined scenarios. I therefore prefer to describe innovation through a testable change to a process and a clearly defined group of participants.

Major industry projects also show the importance of collective preparation. In a standalone prototype, the developer controls the whole environment. A test across institutions requires several teams, contracts and responses to the same incident to be coordinated. The assessment of SUPA’s readiness needs to reflect that transition.

Three further jurisdictions to watch

India, Kazakhstan and Switzerland appeared in our research beyond the main comparison. They warrant separate investigation, but I do not equate them with procedures we have already been through.

India’s GIFT IFSC has an updated FinTech Sandbox Framework, effective from 16 March 2026. It distinguishes regulatory testing with real participants, a technology-focused innovation sandbox, and mechanisms for cooperation between regulators or across borders. This version should be used when assessing the current route. IFSCA, FAQs on the 2026 framework.

In Kazakhstan’s AIFC, the AFSA states that the list of solutions for its FinTech Lab is not exhaustive. The absence of “netting” from the examples therefore does not establish that a model is excluded: its specific activities need to be assessed. AFSA, Solutions Available for Testing.

Switzerland’s FinTech licence is a separate authorisation regime. FINMA describes the ability to accept public deposits of up to CHF 100 million or relevant cryptoassets, subject to restrictions including no investment of the assets or payment of interest; requirements also apply to the Swiss structure and operations. FINMA FinTech Licence.

For SUPA’s current proposed model, where funds remain with financial institutions, the first question is why a regime relating to deposit-taking would be needed at all. Proposed reforms should also be assessed against their published legal status: a bill, a consultation and an authorisation already in force provide different foundations for planning.

The real cost of participation

Incorporation fees and the minimum capital for an ordinary company are convenient figures for a table, but say little about the cost of a financial experiment. SUPA’s budget will depend on the functions agreed and what must be in place before operations begin.

Area of preparation

What drives the cost

Legal model

Number of functions, participants, countries and contractual relationships

Governance and team

Requirements for local presence, expertise and allocation of responsibility

Security

Data volumes, access architecture, independent assessments and recovery

Integrations

Banking partners’ capabilities, testing environments and agreement on interfaces

Participant protection

Potential harm, guarantees, compensation arrangements and handling of complaints

Operations

Reconciliation, monitoring, reporting, incident response and support

Ending the pilot

Completing transactions, transferring records, ending contracts and retaining necessary data

I have not given a single “annual country budget”, because it would mix different costs before the model has been defined. An inexpensive company can require an expensive management structure. Free guidance can help avoid unnecessary licensing. A pilot with a strong local partner may be more viable than a test in a jurisdiction with a formally more flexible programme.

Similarly, we need to distinguish funds already available to the company, a founder’s intention to finance development and a signed commitment to allocate a specified sum. These represent different levels of financial provision in an operational plan.

Exiting a test also needs a budget. If the next stage is not permitted, existing operations must be completed, discrepancies resolved, participants informed and obligations fulfilled. Even where banks hold the funds, there may be costs for restoring records, compensating harm and supporting the completion of the process.

My approach is to assess readiness against the most demanding scenario proposed for admission. A reconciliation demonstration and a live test of legally effective multilateral netting require substantially different preparation.

What founders expect from innovation hubs

Following our Irish correspondence, I became more precise about expectations. The founder of an infrastructure project needs to understand which authority is responsible for which question, which functions should be analysed separately and what evidence will allow the project to move towards testing.

The applicant needs to undertake the legal work with appropriate specialists. In my view, a useful hub can also help organise the next conversation: identify the relevant department, highlight known supervisory questions and explain the available procedures.

That suggests a measure of programme quality. An enquiry should make at least one practical decision clearer: change the allocation of functions, prepare a legal opinion, bring in a particular partner, seek an existing permission or present a limited testing scenario.

If the response leaves all those questions open, a founder can reasonably consider it insufficient for the task. That is a reason to clarify the request and the channel’s remit. I would not judge an entire jurisdiction from one response: different departments and programmes may offer different depths of engagement.

Entrepreneurs should also test their own hypothesis about a regulatory gap. The absence of a licence bearing the product’s name does not establish that the activity is unregulated. Individual functions may fall within existing regimes or need to remain with licensed participants. The real task is to establish whether that allocation allows the proposed model to operate and where an obstacle remains.

How I would choose a route for SUPA

At this stage, I would assess programmes against five questions. Can we demonstrate the part of the product that already works? Is there a specific legal uncertainty? Is an institution willing to participate? Can we provide the necessary limits and participant protection? Is it clear what result the next stage will require?

For preparing and agreeing a first pilot, Spain and the UK seem the most practical routes among those we have explored. Spain allowed us to frame an application around the prototype’s maturity and a proposed testing protocol. The UK route is interesting for discussions about the permissions required and the boundaries of a live test. This is my assessment of suitability, rather than a prediction of decisions on our applications and enquiries.

The Netherlands is important for clarifying the classification of infrastructure functions. Guernsey offers a way to discuss the appropriate regime and the requirements for the operator. Ireland remains relevant for further dialogue based on a more specific legal hypothesis and for monitoring suitable thematic cohorts.

Bahrain and Saudi Arabia require particularly detailed work on a local pilot and institutional participants. South Korea has a strong exemptions mechanism, but requires prior confirmation of an eligible applicant and a local application. Japan and Hong Kong become more interesting when there is a use case aligned with their payments and infrastructure initiatives.

I would not launch the same live test in numerous countries at once. Each jurisdiction adds contracts, reporting, participants and obligations. Several early enquiries are useful when choosing a route; the first agreed experiment needs a manageable scale and sufficient resources.

For me, this comparison has made the work ahead more concrete. We need to demonstrate the functioning prototype, establish the parties’ powers, select an institutional participant, agree a test and measure its results. We can then have an informed discussion about commercial deployment and further jurisdictions.

A regulatory sandbox becomes valuable when it helps make that transition: from an architecture understood by its developer to a model that independent financial institutions can use safely. For SUPA, that will be the main measure of the value of participation.

You might also like

Hide Copyright Text and Social Links