Site navigation

Comment | Contracting for Fintechs: What to Expect

Martin Beveridge

,

Contracting for Fintechs
In this contributed article for DIGIT, Martin Beveridge, senior associate at CMS, offers some guidance for Fintech startups and SMEs on what to expect when entering into a contract for providing services/tech to a UK financial services provider.

You’re a young Fintech company.

You have a transformative proposition that is just what the UK banking sector has been waiting for.

Your people are gifted, dynamic and talented: fizzing with ideas and energy about your product.

Your first pitch to a big Bank has gone unbelievably well. The Bank wants your product and this is your first big customer. Everyone can’t wait to get started on delivery.

Enter the lawyers, stage left…

You will in all likelihood be sent a draft contract running from 50 to 100 pages. This is before any details have been added about what you are providing, the price, the service levels etc..

The document will consist of dense set of legal terms and conditions and 10 to 15 “schedules”, covering a range of topics from information security through to the shade of toast you are permitted to consume on bank premises.

At this point you can see your delivery timetable doubling in length and your enthusiasm seeping away into your keyboard. However if you have read this article you will at least know what to expect and have some idea of why.

The financial services sector is perhaps the most heavily regulated sector in the UK. That is one reason why, when you get that contract, it will resemble War and Peace. Financial services institutions are also by and large immensely conservative and risk-averse (with good reason – they are in the business of handling real people’s money).  Larger ones will also have strict contracting, compliance and risk procedures that must be satisfied before they can put pen to paper.

With that in mind, here are some things to expect:

1. It’s not you, it’s me…

I know you have spent months and several thousand pounds on legal fees drafting the perfect set of customer terms. But unless you are tech behemoth you should quietly file-away any hope of using them to contract with a bank. Most banks and FS institutions will only contract on supplier paper in very exceptional circumstances.

2. Remedies, remedies everywhere (but not for you)

Your customer will expect to have a “toolbox” of contractual remedies which it can deploy to keep you performing on time, at the agreed price and to the agreed standards.

So expect:

  • milestone payments for any development/ implementation work;
  •  liquidated damages for delays;
  •  stringent acceptance testing regimes (with acceptance criteria hard-wired into the contract);
  • service levels and service credits for in-flight services;
  • step-in rights;
  • one-way audit rights;
  • escrow; and
  • an extensive suite of customer termination rights.

Conversely, your remedies will be limited and will generally be about ensuring you get paid. The reason for this imbalance is (mostly) service continuity and ultimately about protecting consumers: the customer will want to really narrow down any possibility that a key
technology supplier can walk off the park and leave end customers without services. This is ultimately about safeguarding good outcomes for consumers.

3. Risky Business

Between 75% to 80% of the contract bulk will be dedicated to risk mitigation and management. Banks and other FS firms are often mandated by regulation (a prime example being the PRA Supervisory Statement SS2/21 on outsourcing) to include lots of provisions in their contracts. So expect extensive schedules dedicated to information security, resilience and business continuity; data protection; exit arrangements; governance and management information.

Meeting your customer’s standard requirements in these areas can place a heavy burden on your management time and resources, particularly if you run a lean operation. However most FS firms should have sourcing and compliance functions that can help work through the detail with you and identify areas where they can be flexible (within regulatory parameters).

4. You’re a Liability

Liability will be the last clause to be agreed and the hardest-fought. Off the bat you will be expected to accept uncapped liability for IP, confidentiality, data protection and security breaches. However if your customer values your proposition and understands that you are start-up with finite resources there should hopefully be scope for negotiation to bring things within your insurable risk envelope.


Recommended reading


Even very experienced negotiators will find it difficult to navigate all these areas. The good news is that UK financial services businesses are becoming increasingly pragmatic and collaborative.

In recent months I’ve personally seen strenuous attempts by various FS customers to become more flexible, more dynamic and easier to deal with for SME and start-up Fintechs.

Banks know that in a competitive market and with the future at stake, it’s “de’il tak the hindmost”.

Really forward-thinking organisations value innovative technology that brings tangible benefits to their customers. If the contract becomes a barrier to embracing that technology a confident customer will be willing to compromise. So if you receive a first draft contract that can be weighed in kilograms rather than ounces, fear not: as Cheryl Tweedy and others have said, you’re worth it.

Martin Beveridge

Senior Associate, CMS

Latest News

AI Infrastructure

Scottish Parliament Votes to Pause All AI Data Centre Applications

Cybersecurity Editor's Picks Security

Cyber Essentials Certifications Rise as SME Uptake Remains Limited

AI Editor's Picks Funding

Edinburgh Graduates’ AI Infrastructure Firm Expanse Raises $5.3m

Featured Finance

Fintech Summit 2026 Countdown Enters Final Three Weeks