Notes from the perimeter.
Working notes on regulated systems — ledger design, BPM, KYC orchestration, AI inside compliance perimeters, and what telco × bank synergy actually means when the regulator asks for evidence.
Build vs buy vs BaaS: the three ways a tier-1 operator launches a wallet, compared honestly.
Every telecom board evaluating embedded finance ends up comparing three paths: build in-house, plug into a BaaS aggregator, or run a partner-led launch. Time-to-live, capex, licence ownership, lock-in, unit economics — the full comparison, including where each path genuinely wins.
Policy, market shift, operational consequence. Why this matters at the board level.
Sequence diagrams, runtime boundaries, failure models, state machines, recovery logic.
Code, ADRs, LangGraph patterns, replay strategies, decision-journal patterns, real deployments.
Build vs buy vs BaaS: the three ways a tier-1 operator launches a wallet, compared honestly.
Every telecom board evaluating embedded finance ends up comparing three paths: build in-house, plug into a BaaS aggregator, or run a partner-led launch. Time-to-live, capex, licence ownership, lock-in, unit economics — the full comparison, including where each path genuinely wins.
Decision journals for regulated runtime: event sourcing, replay, and what a regulator actually queries.
The decision journal sits behind every Coreal deployment, satisfies DORA Art. 5, BCBS 239 lineage, AMLA evidence, and EU AI Act Art. 12 logging from a single source. The engineering deep-dive: schema, event-sourcing pattern, replay engine, retention strategy, what a regulator actually queries.
DORA Audits Don't Start With Your Policies — They Start With Your Last Deployment
DORA examinations in 2026 open with the change log from your last production release, not your governance frameworks. What a Joint Examination Team actually requests on day one — asset register, third-party contracts, incident log, per-release evidence — and where ICT providers stall.
FiDA Makes Your Wallet a Data Broker Whether You Planned for It or Not
The Financial Data Access regulation — FiDA — is in the final stretch of trilogue, with formal adoption expected in mid-2026. It extends PSD2's data-sharing logic to pensions, insurance, investments and mortgages — and reshapes what a wallet is.
Twelve questions to ask any fintech infrastructure vendor before signing.
A bank or insurer's procurement / CTO due diligence checklist. Twelve specific questions, what good answers look like, what red flags mean a vendor isn't DORA-ready, AI-Act-ready, or fit for a regulator audit. Written so the buyer can take it directly to vendor RFP cycles.
The Sponsor Bank Is the Product: Nine Criteria That Decide Whether a Partner-Led Launch Ships
Most fintech teams treat sponsor bank selection as a procurement task.
A Telco Wallet Holding Euro-Stablecoins After July 2026 Needs Two Licences, Not One
Operators running mobile wallets have absorbed e-money regulation before — slowly, through partner-bank arrangements that kept the licence burden off the telco's balance sheet.
The Correspondent Bank Is the Bottleneck, Not the Border
Cross-border remittance latency is not a geography problem.
Verification of Payee Is a Latency Problem Dressed as a Compliance Problem
The European Payments Council's Verification of Payee scheme became mandatory for PSPs operating in the euro area on 9 October 2025, under Article 5c of the revised Instant Payments Regulation (EU …
PSD3 + PSR1: what bank CTOs need to plan before Q4 2026.
Payment Services Directive 3 + Payment Services Regulation 1: trilogue finalising 2026, transition window 2027-28. What changes vs PSD2, what's the practical roadmap for a tier-1 bank, and where Coreal sits in the transition. SCA evolution, open banking premium APIs, fraud liability shifts.
Wave-1 in 90 days for a tier-1 European insurer: claim payouts from 14 days to 38 seconds.
Anonymous field note: how a tier-1 EU insurer modernised motor and travel claim payouts without touching its Guidewire policy admin core. Read-only on policy admin, instant wallet payout, audit trail per claim. Same architecture as telco and bank — different book of record.
EU AI Act for regulated fintech: what's high-risk, what isn't, and how Coreal handles both.
EU AI Act is in transition. February 2025 banned prohibited practices; August 2026 makes high-risk obligations binding. Credit scoring, insurance pricing, biometric onboarding — all in scope. Here's what a fintech actually needs to file, and what Coreal generates automatically.
Cost-to-income math: where 2pp actually comes from.
A CEE tier-1 bank's cost-to-income ratio improved from 54% to 52% in 18 months without redundancies. Anonymous waterfall analysis: where every basis point came from. Why the C-to-I story is not about cutting headcount but about redeploying it.
BCBS 239 + DORA + AMLA: one evidence pack, three regulators.
Most banks treat BCBS 239 (risk-data aggregation), DORA (operational resilience) and AMLA (AML supervision) as three separate compliance programmes. They share roughly 70% of the artefact base. Here's the mapping table — and why running them as one programme cuts evidence-pack labour 60%.
Wave-2 for banks: card-to-card on Coreal ledger, without writing to T24.
Sequel to the Wave-1 KYC field note. How a tier-1 CEE universal bank shipped a card-to-card transfer product on the Coreal ledger in 45 days, with T24 as read-only book of record. Idempotency at the boundary, T+1 reconciliation, zero core writes.
Adjacent vs replacement: why bank-core projects fail at month 18.
Three anonymous EU core-banking-replacement projects, post-mortem. Pattern: ledger cutover collapses under dual-run cost and regulator anxiety. The adjacent pattern — read-only on legacy, build new on Coreal — does not have the same failure mode. Why.
DORA Article 28: what a bank actually files on a fintech ICT provider.
DORA enforced January 2025. Every EU bank now needs a third-party ICT register and an evidence pack per provider. Here's the exact pack Coreal hands the bank for its DORA file — copyable as a baseline.
Wave-1 in 90 days for a tier-1 CEE bank: KYC from 5 days to 38 seconds.
How a tier-1 CEE universal bank modernised customer onboarding without touching the legacy core. Anonymous field note: read-only on core, KYC orchestration on Coreal ledger, AML manual-review FTE down 60%.
Wave-1 in 90 days: how a cross-border corridor actually ships.
A field note on the engineering, licensing, and BSS integration sequence required to go from signed term sheet to a live remittance corridor — with real timelines and where deals typically break.
What FY2025 numbers tell us about the embedded finance opportunity for tier-1 mobile.
An anonymous read of public FY2025 results from a tier-1 EU/CIS mobile operator — and what they imply for the next 36 months of embedded finance.
What a bank brings and what a telco brings — and why neither is enough alone.
A structural analysis of capital, distribution, license and the ledger that joins them.
How telco billing rails become the foundation of embedded finance.
Autopay, dunning, and recurring charges as a fintech primitive — before you write a line of ledger code.
Why a telco joining a bank is not a fintech.
Distribution × billing × identity vs. yet another challenger app.
Hierarchical accounts: the data model under a wallet.
Customer subaccounts, blocked amounts, treasury depth.
KYT on crypto deposits — what regulators actually look at.
Provider patterns, sanctions sources, evidence pack.
Bounded AI: agents inside a replay-safe perimeter.
Suggestions, not decisions. Journals over autonomy.
BPM is the spine of regulated software.
Why workflow engines outlive frontends.
A week in the operator workspace.
What ops actually open, click and worry about.
Licensing topology for cross-border embedded finance.
Partner-first, EU EMI, regional PI — when each makes sense.
Three lines of defense, written in JSON.
Audit-ready governance as code.
Provider gateways: one contract, twelve providers.
Swap card issuer or open-banking provider without touching the ledger.
Curated paths through the archive.
Three long arcs we keep getting asked about. Pick a path; we'll keep it updated as new notes land.
Engineering & policy notes, once a fortnight.
No newsletter blast. A short brief from the team — written for operators, founders and regulators, not for marketers.