At Adfin, we are in the early stages of building something ambitious, and getting compliance right from the start is a core part of that. Payments is a world with increasing regulatory expectations, heightened financial crime risk, and pressure to operate resiliently and prudently. It is not enough to treat compliance as a checkbox; it has to be part of our culture and the way we do business.
When you are an early-stage fintech, building a compliance function comes with unique challenges. There is no off-the-shelf playbook. There are trade-offs. Doing the right things at the right time can be the difference between the business surviving or not.
Here is how we are approaching the challenge, what we have learned so far, and where we are going next.
1. Compliance isn’t a silo, it is a shared responsibility
One of the early critical things to get right is the mindset around compliance responsibility. With a small team, everyone is expected to pitch in and do things that might traditionally fall outside their remit. At Adfin, you might see the CEO building office chairs and the Founders Associate driving a van across the UK to meet customers. The same applies to understanding the compliance requirements we face.
We have always been thoughtful about hiring, and having experienced people helps. Many of our team have worked in regulated businesses before and understand the risks and challenges that come with that. It means people often ask the right questions at the right time and are empowered to speak up.
Compliance considerations tend to surface naturally in different areas, from product and engineering to marketing. Rather than treating these as blockers, we see them as signals that show where the business is maturing, where decisions with regulatory implications need more thought, and where people might need more help to reach the right decision.
2. Your partners are your first regulators
In the earliest stages of a fintech, your first real compliance test often comes from your partners. Whether it is a banking provider, a card acquirer, or a commercial partner, these organisations assess your controls, governance, and people before they agree to work with you. They take a risk on you before you start on the long journey to become regulated yourself.
This creates a dynamic where you have to build credibility and trust from day one. You cannot simply say “we will fix this once we are bigger.” You have to show you are taking compliance seriously even before you are authorised in your own right.
Credibility comes from more than just having documents in place. It is in your roadmap, your decision-making, and your attitude to risk. Firms that want to last in this space need to treat compliance as a competitive advantage, not just a cost centre.
3. Balancing commercial pressure with compliance priorities
In an early-stage company, resources are always limited. Commercial pressures inevitably influence how you allocate them, and compliance is no exception. There are always more controls you could build, more policies you could write, more ways to try to make things 100 per cent failsafe.
Where you focus matters. At Adfin, we take a risk-based approach based on our business model, identifying where the greatest risks lie. One of our key customer segments is accountants and bookkeepers. Adfin helps them collect payments from their customers so they can minimise chasing and focus on their business. To support this, we build compliance and anti-money laundering safeguards into our product design, ensuring the platform is used responsibly and securely.
The aim is not to eliminate all risk but to mitigate it where we can now, while learning and adapting as we grow.
4. No off-the-shelf playbook
When you are building a compliance function in a startup, there is no perfect playbook. Every fintech has a different model, risk profile, and partner ecosystem. At Adfin we look at what the law says, consider our collective past experience (including both successes and failures), experiment where it's safe to do so and implement controls. This happens fast.
Some of our controls are shaped by regulator guidance, while others require more tailored solutions for our business. One size does not fit all, and copy-pasting policies and processes from other firms does not work when your product and customer base are different.
5. Why I joined: building, experimenting, and scaling smart
I joined Adfin because I enjoy building. When you are going from 0 to 1, you have to be deliberate and smart about what you do, every day. I value the freedom to experiment. For example, I have used large language models to prototype simple internal tools, from policy checklists to risk-scoring logic. In a large institution, these kinds of efficiencies could take months and multiple sign-offs. In a startup, you can try, iterate, and implement quickly.
Of course, innovation has boundaries. Regulators do not, and should not, care how fast you can build if it puts customers or the financial system at risk. At the end of the day, even though we’re smaller than other more mature firms, the same laws apply and we have to get it right.
6. What is next for us
We are still early in our journey, but we are building our compliance culture deliberately. Some of our next priorities include:
- Strengthening internal governance without slowing down decision-making
- Being thoughtful about how we scale — it is easy to “know” our customers well now, but how will we achieve the same depth of understanding as we grow
- Automating wherever it is safe and sensible to do so
- Engaging proactively with regulators as we expand
Building a sustainable fintech is not just about growth; it is about earning trust. That trust comes from doing the right thing.
.avif)