Coreal.
Book a working session →
← INSIGHTS·POLICYbuild-vs-buybaaswhite-label-wallet

Build vs buy vs BaaS: the three ways a tier-1 operator launches a wallet, compared honestly.

Every telecom board evaluating embedded finance ends up comparing three paths: build in-house, plug into a BaaS aggregator, or run a partner-led launch. Time-to-live, capex, licence ownership, lock-in, unit economics — the full comparison, including where each path genuinely wins.

M
M. Tymoshenko
Founder · Coreal
20 Jun, 20266 min

The question every board asks in the wrong order

By the time a tier-1 operator's board approves an embedded finance initiative, someone has usually already picked the delivery model — and the evaluation that follows is a justification exercise. The right order is the reverse: the delivery model is the decision. Product scope, licence path, time-to-live, and five-year economics all fall out of it.

There are three real options. Build the product in-house and apply for your own licence. Buy access to a Banking-as-a-Service aggregator and assemble a product on top. Or run a partner-led launch: a sponsor bank holds the licence, a platform partner builds and operates the product, and the operator keeps the brand and the customer. We are the third option, so discount accordingly — but the comparison below is the one we walk through with every prospect, including the rows where we lose.

The comparison

In-house buildBaaS aggregatorPartner-led launch
Time to first live product18–36 months6–12 months90 days (Wave-1)
LicenceYour own EMI/PI applicationAggregator's licence, their perimeterSponsor bank's licence
Upfront capex€15–40M before first customerLow entry, per-account fees€0 — revenue share
Compliance ownershipEntirely yoursShared, contractually fuzzyBank-owned, evidence pack per release
Roadmap controlFullAggregator's backlogJoint, you sign off scope
BSS / billing integrationYou build itRarely offeredRead-only on the event bus, included
Lock-in / exitNone (you own it)High — ledger lives with aggregatorMedium — ledger portable, bank swappable
Unit economics at 1M+ accountsBest, if you survivePer-account fees erode marginRevenue share, scales with usage
Regulatory blast radiusAll yoursAggregator incidents are your incidentsContained at the sponsor bank

Three of these rows decide most deals: time to live, compliance ownership, and what happens at scale. Take them in turn.

Where in-house genuinely wins — and why it usually doesn't matter

If you reach ten million active financial customers, owning the entire stack gives you the best unit economics on the market. No revenue share, no per-account fees, full margin. This is the correct end state for an operator whose financial product has become a primary business line.

The problem is the path, not the destination. An own-licence build means an EMI or PI application from a standing start: a regulator with no track record on you, a compliance function hired before the product exists, and a two-to-three-year window during which the market moves and the board's patience decays. We wrote up the failure pattern for the adjacent case — banks replacing their own cores — in adjacent vs replacement, and the telco version is harsher: the first wave of telco wallets (2008–2016) was almost entirely in-house builds, and almost entirely a graveyard. The reasons haven't changed: top-up is not a financial product, and a billing team is not a bank.

In-house is the right call when two things are simultaneously true: you already operate a licensed financial entity in at least one market (some CIS and African operators do), and your board accepts a 24-month-plus horizon with nine-figure committed spend. If either is false, you are choosing between the other two paths.

What BaaS actually gives you, and where it breaks

The BaaS aggregator pitch is genuinely attractive at the entry point: APIs for accounts, cards and payments, a licence umbrella, sandbox access in days. For a startup or a mid-size brand running an embedded finance experiment, it is often the correct choice — faster than partner-led to a pilot, with no bank negotiation at all.

At tier-1 operator scale, three things break.

Per-account pricing inverts the business case. Aggregator pricing is built for thousands to low hundreds of thousands of accounts. At 5–80M subscribers, per-account and per-transaction fees do not produce a margin structure an operator CFO will sign. The aggregators know this; enterprise deals get renegotiated into something that looks increasingly like a bespoke platform contract — at which point you are running a partner-led launch with a thinner partner.

Nobody integrates your BSS. The single largest asset an operator brings to embedded finance is the billing relationship — autopay, dunning, recurring charges, the rails that already move money monthly. Aggregators integrate against their own ledger and stop there. Building the BSS bridge yourself quietly re-imports a third of the in-house build you were avoiding.

The compliance boundary is contractually fuzzy. When the aggregator's licence takes a regulator hit — and the EU enforcement record of the last five years shows this is not hypothetical — onboarding freezes and remediation programmes land on every brand running on that licence, including yours. You inherited the blast radius without inheriting any control over it. A bank running DORA Article 28 diligence on its ICT providers would never accept this structure; operators accept it because nobody put the question in the RFP.

The partner-led path, stated plainly

The partner-led model splits the three roles that BaaS bundles and in-house concentrates: the sponsor bank holds the licence and owns compliance sign-off; the platform partner builds and operates the product; the operator owns the brand, the distribution, and the customer. Each party does the thing it already knows how to do.

What this buys, concretely:

  • 90 days to a live Wave-1 product — not a sandbox, a live cross-border corridor with real customers. The licence exists on day zero, so the critical path is engineering and bank gates, not regulatory correspondence.
  • A real compliance owner. Every release passes the sponsor bank's security and compliance gates (DORA, MiCA, AML, EU AI Act). The bank's regulator relationship covers the perimeter. The evidence pack is produced per release, not reconstructed at audit time.
  • Capex of zero. Wave-1 is revenue-share. The operator's commitment is people and distribution, not a platform licence fee — which changes the internal approval path from "investment committee" to "commercial deal".
  • BSS integration as the starting point, not an afterthought: read-only on the billing event bus, SIM identity as a KYC asset, the existing app as the distribution surface.

And the honest costs: you share revenue, so at very large scale your unit economics are worse than a successful in-house build. You depend on a sponsor bank, so bank selection is a first-order decision, not paperwork. And the model has a medium lock-in — lower than BaaS because the ledger and product are designed to be portable and the sponsor bank swappable, but it is not zero and nobody should claim otherwise.

The decision in one paragraph

If you already hold a licence and can fund a multi-year build: build, and own everything. If you are running an experiment that may be shut down in a year: BaaS, and keep the exit cheap. If you are a tier-1 operator that intends to put a financial product in front of millions of existing subscribers under its own brand — with a board that wants proof inside two quarters, a CFO who will not sign nine-figure capex, and a regulator-grade audit trail from day one — the partner-led path is the only one of the three that was actually designed for your shape.

Before signing with anyone — us included — take the twelve questions every fintech infrastructure vendor should be able to answer into the RFP. And if you want the economics for your own subscriber base rather than ours, run your own numbers.

RELATED · BY TOPIC
← Back to all notesBook a working session →