Buy a Payment Company vs BaaS vs Starting a Payment Business (2026)
Published · Editorial team, Payment Company for Sale
If you want to run a payments business, there are three realistic starting points: buy an existing payment company, partner with a regulated provider under a Banking-as-a-Service (BaaS) or agency model, or found a new payment service provider and apply for your own authorisation. Each one moves risk, control and cost to a different place.
This guide compares them for one specific case — acquiring a Swiss financial intermediary affiliated with an anti-money-laundering self-regulatory organisation (SRO) — against partnering with an EEA payment institution (PI), e-money institution (EMI) or bank, and against building a new PSP. The key point to keep in mind throughout: a Swiss SRO-supervised intermediary is not equivalent to an EU EMI authorisation, an EU payment institution licence or a banking licence.
The three routes, defined
1. Acquiring a Swiss SRO-supervised payment intermediary
Under the Swiss Anti-Money Laundering Act (AMLA), financial intermediaries outside the banking sector — for example businesses providing payment-transaction services or certain crypto services — must meet AML due-diligence duties. Those not otherwise supervised by FINMA must join a self-regulatory organisation recognised and supervised by FINMA. FINMA describes SROs as the bodies that monitor their members' compliance with AML duties (FINMA: SROs).
Buying such a company is a share deal: you acquire the legal entity, its SRO membership, its existing governance and any contracts that survive the change of control. That is different from licensing software. A software licence gives you technology; it does not give you a legal entity, an AML framework or a regulatory status.
2. Partnering with a regulated PI, EMI or bank (BaaS)
In a BaaS model, a licensed institution provides accounts, payment execution, card issuing or e-money under its own authorisation, and you build the customer-facing product on top. In the EEA, payment institutions are authorised under PSD2 (Directive (EU) 2015/2366) and e-money institutions under EMD2 (Directive 2009/110/EC). Your partner remains the regulated party and keeps final say on onboarding, risk appetite and termination.
3. Founding a new PSP
You incorporate, build governance and an AML/compliance function, apply for the authorisation your model needs — SRO affiliation in Switzerland, PI or EMI authorisation in an EEA member state, or a FINMA banking or fintech licence for deposit-taking — and then onboard banking and scheme partners. You own everything, and you carry every step.
Regulatory permissions: Switzerland vs EEA/EU
The most common misunderstanding in this market is treating different statuses as equivalent. They are not.
- Swiss SRO affiliation is AML supervision. It does not authorise accepting public deposits; in Switzerland that generally requires a banking licence or the fintech licence described by FINMA (banks, fintech licence). Swiss banking law contains specific exceptions — such as for certain settlement accounts — whose conditions must be verified by counsel for your exact flow of funds.
- EEA payment institution authorisation under PSD2 covers the payment services listed in Annex I of the Directive, with initial capital tiers set out in Article 7 and safeguarding duties in Article 10. Authorised institutions can passport across the EEA under the Directive's notification procedure.
- EEA e-money institution authorisation under EMD2 additionally permits issuing electronic money, with an initial capital requirement set in the Directive and its own safeguarding rules.
- Crypto-asset services in the EU fall under MiCA (Regulation (EU) 2023/1114), which has its own authorisation for crypto-asset service providers. A Swiss approval of a VASP business model under AML rules is not a MiCA authorisation.
You can check whether an EEA firm is authorised on the EBA register of payment and e-money institutions; the EBA's payment services and e-money hub collects its guidelines and technical standards. Swiss SRO status, by contrast, is generally verified with the relevant SRO itself.
Practical consequence: Swiss SRO status does not passport into the EU, and it does not automatically permit regulated custody, exchange or deposit-like services in every jurisdiction. If your customers are in the EEA, you will likely need either an EEA-authorised partner or your own EEA authorisation for in-scope activities.
Side-by-side comparison
| Factor | Acquire Swiss SRO intermediary | BaaS / regulated partner | New PSP |
|---|---|---|---|
| Legal entity and governance | Existing entity; inherits history (diligence needed) | Yours is unregulated; partner's entity is regulated | New, clean entity; all built from scratch |
| Regulatory status | Swiss AML supervision via SRO; not a bank, PI or EMI licence | Relies on partner's licence and scope | Whatever you apply for and obtain |
| Contract / business risk | Hidden liabilities; mitigated by warranties and diligence | Partner concentration; partner can reprice or terminate | Execution risk; application may be delayed or refused |
| Bank and rail access | Existing relationships, subject to change-of-control review | Through partner's rails | Must be negotiated from zero |
| AML controls | Existing framework and officer; buyer must keep it effective | Partner's framework; you follow its policies | Must be designed, documented and staffed |
| Customer funds | Depends on structure and providers; verify safeguarding and settlement-account limits | Held and safeguarded by the regulated partner | Your obligation under your licence |
| Operational systems | Bring or license your own platform | Partner APIs; limited customisation | Build or license |
| EEA market access | No passport; partner or local licence needed | Depends on partner's passports | Passport if you obtain an EEA licence |
| Control over roadmap | High | Low to medium | High |
Bank and payment-rail access
Access to accounts and payment rails is usually the real bottleneck, not technology. An existing company with onboarded bank or EMI relationships can save negotiation effort, but those relationships are not assets you simply inherit: most providers reserve rights to review, re-onboard or exit on a change of ownership.
In the EU, access is slowly widening. The Instant Payments Regulation (EU) 2024/886 amended the settlement-finality framework so that payment institutions and e-money institutions can participate in designated payment systems, subject to conditions. That benefits EEA-authorised firms; it does not extend to a Swiss SRO-affiliated intermediary.
A BaaS partner gives you rail access on day one of the contract, but on its terms. A new PSP has to win banking relationships while still unproven, which many founders find the hardest step.
AML controls and customer funds
Whatever route you choose, AML is not outsourced away. In an acquisition you inherit a framework — policies, risk assessment, an AML officer, audit history — and must keep it effective under new ownership. Ask for the most recent SRO audit reports and any findings. In a BaaS arrangement your partner's policies apply and it will audit you. In a new PSP, regulators will expect complete documentation before authorisation.
Customer-fund treatment deserves its own legal analysis. EEA PIs and EMIs must safeguard funds under PSD2 Article 10 and the equivalent EMD2 provisions. In Switzerland, holding customer money can bring you close to the deposit-taking rules; the structure — which provider holds funds, for how long, and in whose name — determines whether a banking or fintech licence would be required. Do not assume an SRO membership answers that question.
Change of control and partner onboarding
Three separate approvals or notifications can apply when you buy a payment company:
- Regulator or SRO. EEA PIs and EMIs are subject to qualifying-holding rules, so buying one generally requires prior assessment by the competent authority. For a Swiss SRO member, the SRO's regulations govern what must be notified and when, typically including fit-and-proper information on new owners and managers.
- Providers. Banks, EMIs, card programme managers and KYC vendors run their own reviews.
- Counterparties and staff. Office leases, outsourced officers and key individuals may need new agreements.
For the company listed on this site, the seller states that ownership transfers on completion of the transaction documents, that no regulatory approval is required for the ownership change, and that the SRO is notified after completion. Treat this as a seller statement to confirm during diligence.
Five-year cost of ownership (no invented figures)
Published "average costs" for launching a PSP vary so widely that they are rarely useful. Instead of inventing numbers, use this matrix to collect real quotes. Fill each cell from term sheets, provider quotes and your own payroll.
| Cost category | Acquisition | BaaS partnership | New PSP |
|---|---|---|---|
| Upfront | Purchase price; legal, tax and technical diligence | Integration and onboarding fees per partner contract | Incorporation, application preparation, regulatory capital |
| Regulatory | SRO membership and AML audit fees | Usually embedded in partner fees | Licence or SRO fees; audits; capital buffers |
| People | Director, AML officer, operations team | Product and partner-management team | Full management, compliance and operations team |
| Banking and rails | Account and transaction fees | Per-account / per-transaction partner pricing | Account and scheme fees once onboarded |
| Technology | Platform licence, hosting, maintenance | Partner API fees; your front end | Build or licence; hosting; security testing |
| Exit / switching | Resale value of entity (uncertain) | Migration cost if partner terminates | Entity value if successful |
Two data points from the listing on this site, stated by the seller and subject to confirmation: the Swiss resident director and AML officer together have a base cost of CHF 4,500–5,000 per month, and banking costs are approximately CHF 5,000 per month, with SRO, office, accounting, tax and AML-audit costs additional. See the listing FAQ. Other routes have different cost structures and should be quoted on equal terms.
Time-to-market without guarantees
Speed claims are where this market is least reliable. The honest comparison is about which steps each route removes, not a number of weeks:
- Acquisition removes incorporation and initial SRO affiliation; it still requires diligence, closing, provider reviews, platform deployment and integrations.
- BaaS removes your own licensing; it still requires partner due diligence, contract negotiation, integration and partner sign-off on your programme.
- A new PSP requires every step, and the authorisation timeline is controlled by the regulator and the completeness of your file.
The company on this site makes no fixed launch-date commitment; commercial launch depends on deployment scope, configuration, integrations and provider onboarding.
Pros and cons
| Route | Strengths | Weaknesses |
|---|---|---|
| Acquire | Own entity and AML framework from completion; existing relationships to build on; history that providers can review | Inherited risks; relationships may not survive; Swiss status only; purchase price and ongoing fixed costs |
| BaaS | Fastest path to a working product where the partner is licensed; less compliance headcount | Dependency on one partner; limited control; margin shared; termination risk |
| New PSP | Clean history; full control; EEA passport if you obtain an EEA licence | Longest and least predictable; capital and staff before revenue; banking access is hard for new entrants |
Which route is best for whom
- Acquisition suits investors or operators who want their own Swiss legal entity with AML supervision, plan to serve customers where that status is adequate (or partner where it is not), and have the people to run compliance. Compare it with building from scratch.
- BaaS suits product teams validating demand, brands adding embedded finance, or companies whose customers are mostly in the partner's licensed markets.
- New PSP suits well-capitalised teams with a long horizon, a specific regulatory need (for example EEA passporting or e-money issuance) and appetite for running the authorisation process.
Many businesses combine routes: an owned Swiss entity for some activities plus regulated partners for accounts, cards or EEA customers. The technology question that follows — gateway, orchestration or core fintech software — is covered in our companion guide on payment gateway vs orchestration vs core fintech software.
Buyer checklist
- Obtain written confirmation of SRO membership status, approved business model and any conditions directly from the SRO.
- Review the last SRO/AML audit reports, findings and remediation.
- Map every intended activity and customer country to the permission it needs (Swiss, EEA, MiCA, local).
- Ask each bank, EMI and vendor in writing whether the relationship survives a change of control, and on what conditions.
- Confirm how customer funds will be held and whether any structure approaches Swiss deposit-taking rules.
- Check corporate records, share capital, tax filings and litigation; negotiate warranties and indemnities.
- Confirm who the director and AML officer are, their contract terms and their availability after closing.
- Separate the share purchase from any software licence; read each licence for scope, IP ownership and source-code rights.
- Build the five-year cost matrix above from real quotes for at least two routes.
- Plan your own compliance resourcing; acquisition does not replace it.
For a longer due-diligence list, see the payment company acquisition checklist.
Frequently asked questions
Is a Swiss SRO-affiliated company the same as an EU payment institution or EMI?
No. SRO affiliation means the company is supervised for anti-money-laundering compliance by a FINMA-recognised self-regulatory organisation under the Swiss AMLA. An EU payment institution or e-money institution is authorised by an EEA national competent authority under PSD2 or EMD2, with capital, safeguarding and passporting rules. The two statuses are not interchangeable.
Is an SRO-affiliated financial intermediary a bank?
No. Accepting deposits from the public on a commercial basis in Switzerland generally requires a FINMA banking licence or a FINMA fintech licence. SRO membership is an AML supervision framework and does not confer either licence.
Can a Swiss SRO-affiliated company serve EU customers?
Swiss status does not passport into the EU. Whether a particular cross-border activity is permitted depends on each target country's rules, how and where the service is provided, and whether a locally authorised partner is used. Obtain local legal advice for each market before onboarding customers there.
Does buying the company transfer its bank and EMI relationships?
Not automatically. Banks, EMIs and other providers usually have change-of-control, re-KYC or termination clauses. Confirm each provider's position in writing during due diligence and plan for the possibility that some relationships must be re-onboarded.
Is regulatory approval needed to change the owner of a Swiss SRO member?
Requirements depend on the specific SRO's regulations and the company's activities. For the company listed on this site, the seller states that no regulatory approval is required for the ownership change and that the SRO must be notified after completion. Buyers should verify this against the SRO's current rules.
When is a BaaS partnership the better choice?
When you want to test a product quickly in a market where your partner already holds the needed authorisation, and you accept that the partner controls key decisions such as risk appetite, onboarding policy, pricing and termination. It suits product-led teams more than buyers who need their own legal entity and compliance function.
How long does starting a new PSP take?
There is no reliable fixed timeline. Authorisation periods depend on the regulator, application completeness, capital, governance and AML documentation, and banking partners run their own onboarding. Treat any guaranteed timeline with caution.
What does the acquisition route not solve?
Acquiring an entity does not remove the need for your own capable management, AML resources, provider contracts, local permissions for target markets or ongoing compliance costs. It removes the incorporation and initial SRO affiliation steps, not the work of operating a regulated business.
Sources and method
Legal statements are drawn from regulators and official legal texts; product descriptions come from each vendor's own public website as accessed on 11 October 2026 and are vendor claims, not independent test results. This guide is general information, not legal, tax or investment advice. Obtain qualified advice for your jurisdiction and transaction.
- Self-regulatory organisations (SROs) — FINMA, Swiss Financial Market Supervisory Authority
- Anti-Money Laundering Act (AMLA, SR 955.0) — Swiss Federal Law (Fedlex)
- Banks and securities firms – authorisation — FINMA
- FinTech licence and fintech authorisation — FINMA
- Directive (EU) 2015/2366 on payment services (PSD2) — EUR-Lex, Official Journal of the EU
- Directive 2009/110/EC on electronic money institutions (EMD2) — EUR-Lex
- Payment services and electronic money — European Banking Authority (EBA)
- Register of payment and electronic money institutions — EBA
- Regulation (EU) 2024/886 on instant credit transfers in euro — EUR-Lex
- Regulation (EU) 2023/1114 on markets in crypto-assets (MiCA) — EUR-Lex