Coreal.
Book a working session →
06London · engineering & policy notes

Notes from the perimeter.

Working notes on regulated systems — ledger design, BPM, KYC orchestration, AI inside compliance perimeters, and what telco × bank synergy actually means when the regulator asks for evidence.

ARTICLES
31
SUBSCRIBERS
4,180
CATEGORIES
5
LAST UPDATE
20 Jun, 2026
Featured
FEATURED · POLICY

Build vs buy vs BaaS: the three ways a tier-1 operator launches a wallet, compared honestly.

Every telecom board evaluating embedded finance ends up comparing three paths: build in-house, plug into a BaaS aggregator, or run a partner-led launch. Time-to-live, capex, licence ownership, lock-in, unit economics — the full comparison, including where each path genuinely wins.

M
M. Tymoshenko
Founder · Coreal
6 min · 20 Jun, 2026Read brief →
·Read by audience
EXECUTIVE20 pieces
Founders · CFOs · Heads of Risk

Policy, market shift, operational consequence. Why this matters at the board level.

Filter: POLICY · COMPLIANCE
ARCHITECTURE6 pieces
CTOs · Staff engineers · Heads of Platform

Sequence diagrams, runtime boundaries, failure models, state machines, recovery logic.

Filter: ENGINEERING · AI
IMPLEMENTATION5 pieces
Engineers · Compliance practitioners

Code, ADRs, LangGraph patterns, replay strategies, decision-journal patterns, real deployments.

Filter: FIELD NOTES
SEARCH31 / 31
SORT
POLICYNEW
01

Build vs buy vs BaaS: the three ways a tier-1 operator launches a wallet, compared honestly.

Every telecom board evaluating embedded finance ends up comparing three paths: build in-house, plug into a BaaS aggregator, or run a partner-led launch. Time-to-live, capex, licence ownership, lock-in, unit economics — the full comparison, including where each path genuinely wins.

#build-vs-buy#baas#white-label-wallet
20 Jun, 2026 · M. Tymoshenko6 min
ENGINEERINGNEW
02

Decision journals for regulated runtime: event sourcing, replay, and what a regulator actually queries.

The decision journal sits behind every Coreal deployment, satisfies DORA Art. 5, BCBS 239 lineage, AMLA evidence, and EU AI Act Art. 12 logging from a single source. The engineering deep-dive: schema, event-sourcing pattern, replay engine, retention strategy, what a regulator actually queries.

#decision-journal#event-sourcing#replay
17 Jun, 2026 · I. Kovalenko13 min
COMPLIANCENEW
03

DORA Audits Don't Start With Your Policies — They Start With Your Last Deployment

DORA examinations in 2026 open with the change log from your last production release, not your governance frameworks. What a Joint Examination Team actually requests on day one — asset register, third-party contracts, incident log, per-release evidence — and where ICT providers stall.

#dora#enforcement#ict-risk
13 Jun, 2026 · R. Sadovnikov6 min
POLICYNEW
04

FiDA Makes Your Wallet a Data Broker Whether You Planned for It or Not

The Financial Data Access regulation — FiDA — is in the final stretch of trilogue, with formal adoption expected in mid-2026. It extends PSD2's data-sharing logic to pensions, insurance, investments and mortgages — and reshapes what a wallet is.

#fida#open-finance#open-banking
13 Jun, 2026 · M. Tymoshenko6 min
POLICYNEW
05

Twelve questions to ask any fintech infrastructure vendor before signing.

A bank or insurer's procurement / CTO due diligence checklist. Twelve specific questions, what good answers look like, what red flags mean a vendor isn't DORA-ready, AI-Act-ready, or fit for a regulator audit. Written so the buyer can take it directly to vendor RFP cycles.

#procurement#vendor-due-diligence#rfp
13 Jun, 2026 · M. Tymoshenko13 min
POLICYNEW
06

The Sponsor Bank Is the Product: Nine Criteria That Decide Whether a Partner-Led Launch Ships

Most fintech teams treat sponsor bank selection as a procurement task.

#sponsor-bank#partner-led#vendor-selection
13 Jun, 2026 · M. Tymoshenko6 min
COMPLIANCENEW
07

A Telco Wallet Holding Euro-Stablecoins After July 2026 Needs Two Licences, Not One

Operators running mobile wallets have absorbed e-money regulation before — slowly, through partner-bank arrangements that kept the licence burden off the telco's balance sheet.

#mica#stablecoin#emt
13 Jun, 2026 · I. Kovalchuk5 min
POLICYNEW
08

The Correspondent Bank Is the Bottleneck, Not the Border

Cross-border remittance latency is not a geography problem.

#stablecoin#corridors#remittance
13 Jun, 2026 · A. Avramenko6 min
ENGINEERINGNEW
09

Verification of Payee Is a Latency Problem Dressed as a Compliance Problem

The European Payments Council's Verification of Payee scheme became mandatory for PSPs operating in the euro area on 9 October 2025, under Article 5c of the revised Instant Payments Regulation (EU …

#vop#sepa-instant#instant-payments
13 Jun, 2026 · A. Avramenko6 min
COMPLIANCENEW
10

PSD3 + PSR1: what bank CTOs need to plan before Q4 2026.

Payment Services Directive 3 + Payment Services Regulation 1: trilogue finalising 2026, transition window 2027-28. What changes vs PSD2, what's the practical roadmap for a tier-1 bank, and where Coreal sits in the transition. SCA evolution, open banking premium APIs, fraud liability shifts.

#psd3#psr1#open-banking
10 Jun, 2026 · H. Kowalczyk9 min
FIELD NOTESNEW
11

Wave-1 in 90 days for a tier-1 European insurer: claim payouts from 14 days to 38 seconds.

Anonymous field note: how a tier-1 EU insurer modernised motor and travel claim payouts without touching its Guidewire policy admin core. Read-only on policy admin, instant wallet payout, audit trail per claim. Same architecture as telco and bank — different book of record.

#insurance#insurtech#guidewire
06 Jun, 2026 · I. Kovalenko11 min
COMPLIANCENEW
12

EU AI Act for regulated fintech: what's high-risk, what isn't, and how Coreal handles both.

EU AI Act is in transition. February 2025 banned prohibited practices; August 2026 makes high-risk obligations binding. Credit scoring, insurance pricing, biometric onboarding — all in scope. Here's what a fintech actually needs to file, and what Coreal generates automatically.

#eu-ai-act#ai-governance#high-risk
03 Jun, 2026 · H. Kowalczyk12 min
POLICYNEW
13

Cost-to-income math: where 2pp actually comes from.

A CEE tier-1 bank's cost-to-income ratio improved from 54% to 52% in 18 months without redundancies. Anonymous waterfall analysis: where every basis point came from. Why the C-to-I story is not about cutting headcount but about redeploying it.

#cost-to-income#cfo#bank
30 May, 2026 · M. Tymoshenko12 min
COMPLIANCENEW
14

BCBS 239 + DORA + AMLA: one evidence pack, three regulators.

Most banks treat BCBS 239 (risk-data aggregation), DORA (operational resilience) and AMLA (AML supervision) as three separate compliance programmes. They share roughly 70% of the artefact base. Here's the mapping table — and why running them as one programme cuts evidence-pack labour 60%.

#bcbs-239#dora#amla
27 May, 2026 · H. Kowalczyk11 min
FIELD NOTESNEW
15

Wave-2 for banks: card-to-card on Coreal ledger, without writing to T24.

Sequel to the Wave-1 KYC field note. How a tier-1 CEE universal bank shipped a card-to-card transfer product on the Coreal ledger in 45 days, with T24 as read-only book of record. Idempotency at the boundary, T+1 reconciliation, zero core writes.

#wave-2#card-to-card#bank
23 May, 2026 · I. Kovalenko11 min
POLICYNEW
16

Adjacent vs replacement: why bank-core projects fail at month 18.

Three anonymous EU core-banking-replacement projects, post-mortem. Pattern: ledger cutover collapses under dual-run cost and regulator anxiety. The adjacent pattern — read-only on legacy, build new on Coreal — does not have the same failure mode. Why.

#core-banking#modernisation#strategy
20 May, 2026 · M. Tymoshenko12 min
COMPLIANCENEW
17

DORA Article 28: what a bank actually files on a fintech ICT provider.

DORA enforced January 2025. Every EU bank now needs a third-party ICT register and an evidence pack per provider. Here's the exact pack Coreal hands the bank for its DORA file — copyable as a baseline.

#dora#compliance#bank
16 May, 2026 · H. Kowalczyk9 min
FIELD NOTESNEW
18

Wave-1 in 90 days for a tier-1 CEE bank: KYC from 5 days to 38 seconds.

How a tier-1 CEE universal bank modernised customer onboarding without touching the legacy core. Anonymous field note: read-only on core, KYC orchestration on Coreal ledger, AML manual-review FTE down 60%.

#bank#core-banking#kyc
09 May, 2026 · H. Kowalczyk7 min
FIELD NOTESNEW
19

Wave-1 in 90 days: how a cross-border corridor actually ships.

A field note on the engineering, licensing, and BSS integration sequence required to go from signed term sheet to a live remittance corridor — with real timelines and where deals typically break.

#wave-1#corridor#remittance
07 May, 2026 · I. Kovalenko7 min
POLICYNEW
20

What FY2025 numbers tell us about the embedded finance opportunity for tier-1 mobile.

An anonymous read of public FY2025 results from a tier-1 EU/CIS mobile operator — and what they imply for the next 36 months of embedded finance.

#embedded-finance#telco#fy25
04 May, 2026 · M. Tymoshenko9 min
POLICYNEW
21

What a bank brings and what a telco brings — and why neither is enough alone.

A structural analysis of capital, distribution, license and the ledger that joins them.

#telco#bank#synergy
29 Apr, 2026 · M. Tymoshenko5 min
POLICYNEW
22

How telco billing rails become the foundation of embedded finance.

Autopay, dunning, and recurring charges as a fintech primitive — before you write a line of ledger code.

#telco#billing#autopay
27 Apr, 2026 · M. Tymoshenko4 min
POLICY
23

Why a telco joining a bank is not a fintech.

Distribution × billing × identity vs. yet another challenger app.

#telco#fintech#distribution
24 Apr, 2026 · M. Tymoshenko3 min
ENGINEERING
24

Hierarchical accounts: the data model under a wallet.

Customer subaccounts, blocked amounts, treasury depth.

#ledger#accounts#data-model
18 Apr, 2026 · A. Avramenko2 min
COMPLIANCE
25

KYT on crypto deposits — what regulators actually look at.

Provider patterns, sanctions sources, evidence pack.

#kyt#crypto#compliance
12 Apr, 2026 · R. Sadovnikov1 min
AI
26

Bounded AI: agents inside a replay-safe perimeter.

Suggestions, not decisions. Journals over autonomy.

#ai#compliance#bounded-ai
06 Apr, 2026 · Y. Oliinyk2 min
ENGINEERING
27

BPM is the spine of regulated software.

Why workflow engines outlive frontends.

#bpm#workflows#engineering
28 Mar, 2026 · A. Avramenko2 min
FIELD NOTES
28

A week in the operator workspace.

What ops actually open, click and worry about.

#operations#field-notes#operator-workspace
22 Mar, 2026 · L. Davydenko1 min
POLICY
29

Licensing topology for cross-border embedded finance.

Partner-first, EU EMI, regional PI — when each makes sense.

#licensing#cross-border#emi
15 Mar, 2026 · I. Kovalchuk2 min
COMPLIANCE
30

Three lines of defense, written in JSON.

Audit-ready governance as code.

#compliance#governance#policy-as-code
08 Mar, 2026 · I. Kovalchuk1 min
ENGINEERING
31

Provider gateways: one contract, twelve providers.

Swap card issuer or open-banking provider without touching the ledger.

#payment-orchestration#engineering#providers
01 Mar, 2026 · A. Avramenko2 min
·Subscribe

Engineering & policy notes, once a fortnight.

No newsletter blast. A short brief from the team — written for operators, founders and regulators, not for marketers.

4,180 subscribers · operators, founders, regulators · zero spam