Embedded Finance: The Next Big Shift in Digital Financial Services

Picture of Mariam Laouiti
Mariam Laouiti

Author

Smiling woman in a business suit uses a smartphone in an office, with blurred graphs on a screen in the background, suggesting data analysis.

Embedded finance is the integration of regulated financial products (payments, lending, accounts, insurance) directly into non-financial software, so the customer never leaves the platform to transact. The shift is not theoretical. McKinsey projects that by 2030 embedded finance could account for 10 to 15 percent of banking revenue pools and initiate 20 to 25 percent of retail and SME lending, up from 5 to 10 percent today (McKinsey, July 2024). The revenue is moving from where money is held to where decisions are made.

For platforms in the UAE and wider MENA, the timing matters. The Central Bank of the UAE made Open Finance a mandatory, licensed framework in 2025, and the MENA embedded finance market is forecast to grow from USD 11.2 billion in 2024 to USD 37.7 billion by 2029 (ResearchAndMarkets, 2025). This post covers what embedded finance is, how the architecture works, where the regulation sits in the UAE, and what a CTO or finance director should weigh before building it.

Key Takeaways

  • Embedded finance puts payments, credit, and accounts inside non-financial software through APIs and Banking-as-a-Service, so the bank becomes infrastructure rather than the destination.
  • McKinsey projects embedded finance could reach 10 to 15 percent of banking revenue pools by 2030; Bain estimates roughly USD 3.5 trillion in transaction volume and USD 500 billion in annual revenue at that horizon.
  • In the UAE, the CBUAE Open Finance Regulation (Circular 3 of 2025, in force 10 July 2025) makes participation mandatory for licensees and enables transaction initiation from third-party platforms, the legal mechanism embedded finance runs on.
  • The MENA embedded finance market is forecast to grow from USD 11.2 billion (2024) to USD 37.7 billion by 2029 (ResearchAndMarkets), driven by Aani instant payments, the Dubai Cashless Strategy, and 83 percent mobile banking adoption.
  • The hard part is not the API. It is licensing, KYC and AML controls, ledger reconciliation, and data residency under the UAE PDPL.

What embedded finance actually is

Embedded finance means a non-financial business offers financial products inside its own platform, without sending the customer to a bank, a payment page, or a separate app. A logistics platform that advances working capital to its carriers is doing embedded lending. A retail app that issues a branded wallet is doing embedded banking. A checkout that splits a purchase into instalments is doing embedded credit.

Embedded finance: financial services (payments, accounts, lending, insurance) delivered inside non-financial software, so the user transacts in context instead of switching to a bank.

The distinction that matters for a buyer is ownership. The platform owns the customer relationship and the interface. A licensed institution owns the regulated activity (holding funds, extending credit, underwriting risk). Embedded finance is the plumbing that lets the first borrow the capability of the second. That separation is why a software company can ship a financial product without becoming a bank, and why the licensing question, not the code, decides whether the product is legal.

How the architecture works

Three layers make embedded finance possible: APIs that expose financial functions, a Banking-as-a-Service provider that holds the license and the regulated infrastructure, and the platform that designs the experience on top.

Banking-as-a-Service (BaaS): a licensed bank or financial institution that rents its regulated capabilities (accounts, card issuing, payment rails, compliance) to other businesses through APIs.

The platform calls an API to open a virtual account, initiate a payment, or originate a loan. The BaaS provider executes that request against its regulated systems, handles the movement of funds, and returns a result. Identity verification, sanctions screening, and transaction monitoring sit in between as their own services. The platform never touches the core ledger directly. It orchestrates.

This is where most embedded finance projects underestimate the work. The API call is the visible 10 percent. Reconciliation between the platform’s records and the BaaS ledger, the handling of failed and reversed transactions, the KYC and AML workflows, and the audit trail a regulator will ask for are the other 90 percent. A mismatch between what the platform shows a user and what the underlying ledger holds is not a display bug. It is a compliance and trust failure. Building embedded finance is closer to fintech app development with a banking backend than to adding a checkout button.

The building blocks: payments, lending, accounts, insurance

Embedded payments let a platform process transactions inside its own flow rather than redirecting to an external gateway. This is the most mature category and the easiest to ship, because the regulated activity (acquiring) is well understood and widely available.

Embedded lending and Buy Now, Pay Later put credit at the point of decision. A buyer sees an instalment option at checkout; a small business sees a working-capital offer inside the software it already uses to run operations. The platform has data the lender does not (purchase history, cash flow, behaviour), which makes the underwriting faster and the offer more relevant. The credit risk and the license still belong to the lender.

Embedded banking gives a platform’s users virtual accounts, wallets, or branded cards, and embedded insurance attaches cover at the moment of purchase or booking. In every case the pattern holds: the platform owns the moment and the interface, a licensed institution owns the risk and the regulatory perimeter, and an API connects them.

Why the model is reshaping financial services

The economic argument is distribution. Banks have historically owned both the product and the channel. Embedded finance separates them: the platform with daily user engagement becomes the channel, and the bank that wins is the one that becomes the best infrastructure, not the one with the best app. McKinsey estimates embedded finance channels could initiate 20 to 25 percent of retail banking sales to individuals and SMEs by 2030 (McKinsey, July 2024). Bain & Company puts the prize at roughly USD 3.5 trillion in transaction volume and USD 500 billion in annual revenue at the same horizon.

The experience argument is friction. Every redirect, separate login, and “you will be taken to our payment partner” is a point where a transaction can fail. In commerce, abandoned carts and dropped approvals are measurable revenue, and the conversion lift from keeping the user in one context is the reason platforms invest.

The data argument is underwriting and personalisation. A platform sees behaviour a standalone bank never does, which improves credit decisions, fraud detection, and the relevance of the next offer. The same data raises the obligations: under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), how that financial data is stored, processed, and transferred is a governed activity, not a free input.

The UAE regulatory layer: Open Finance, Aani, and the new banking law

The UAE has moved faster than most markets to give embedded finance a legal foundation. In 2025 the Central Bank of the UAE updated its Open Finance Regulation through Circular 3 of 2025, in force from 10 July 2025. Participation is mandatory for licensees, who must give framework participants access to customer data and the ability to initiate transactions on customer accounts (CBUAE Rulebook, Open Finance Regulation).

Open Finance: a regulated framework requiring financial institutions to share customer data and allow third-party platforms to initiate transactions on a customer’s behalf, with consent. It is the legal mechanism that makes embedded finance possible at scale.

Transaction initiation is the part that matters for embedded products. It lets a customer execute a payment directly from a bank account through a third-party platform, which is precisely the capability an embedded checkout or wallet needs. The framework sits on national rails operated by Al Etihad Payments, including Aani, the instant payments platform, and the Jaywan domestic card scheme. Federal Decree-Law No. 6 of 2025 then widened the regulatory perimeter, unifying banking, fintech, and insurance and explicitly recognising open finance services as a licensed activity.

The market context is favourable. Mobile banking adoption in the UAE crossed 83 percent in 2025, around 89 percent of consumers use digital-first bank accounts (Emirates NBD / PwC), and the Dubai Cashless Strategy targets 90 percent cashless transactions by 2026. Demand for in-context financial products is already there; the regulation now tells builders how to meet it legally.

Where it lands: commerce, SaaS, healthcare, mobility

In retail and e-commerce, embedded payments and instalment credit are close to a default expectation. Integrated checkout reduces abandonment, and regional rails such as Tabby and Tamara have normalised pay-later at the point of sale. The platform that keeps payment, financing, and refund inside one flow holds the customer longer.

In vertical SaaS, embedded finance is becoming a revenue line rather than a feature. Software that runs a clinic, a restaurant, or a logistics operation can add invoicing, expense accounts, and working-capital lending on top of the workflow it already owns. Because the software holds the operational data, the financial product underwrites better and attaches more naturally than a bank approaching the same business cold.

In healthcare, embedded payment plans let patients spread treatment costs, while digital billing and insurance verification reduce administrative load. Data residency under UAE healthcare IT rules applies here, so the financial layer has to respect the same handling requirements as clinical data. In mobility, ride-hailing and subscription transport settle payments automatically after the service, removing the transaction from the user’s attention entirely. The common thread, visible across our case studies, is that the strongest embedded finance sits where a platform already owns a high-frequency moment.

What to weigh before you build

The first decision is licensing, not technology. A platform can use a BaaS provider’s license, pursue its own, or operate under a regulatory sandbox. Each path has different cost, control, and time implications, and the UAE offers structured routes through the CBUAE and the financial free zones (DIFC, ADGM). Choosing wrong here is expensive to unwind later.

The second is the control stack: KYC, AML, sanctions screening, transaction monitoring, and the audit trail. These are the conditions of staying licensed, and they have to be designed in from the first transaction, not retrofitted after launch.

The third is the ledger. Reconciliation between the platform’s view and the regulated provider’s ledger is the operational heart of an embedded product, and failed payments, reversals, and partial settlements all have to be handled deterministically. The fourth is data governance under the PDPL, with full compliance expected by January 2027. Treat these four as engineering problems from day one and you ship something a regulator and a customer can both trust. Treat them as paperwork and it breaks under load.

Frequently asked questions

What does it cost to build an embedded finance product?

There is no fixed price, because cost is driven by the regulated activity, the licensing path, and the depth of the integration. Embedded payments on a BaaS provider’s license sit at one end. A platform pursuing its own license with custom underwriting and ledger infrastructure sits at the other. The honest answer is that the engagement shape determines the number. The most useful first step is a short scoping conversation about which financial products you want, in which jurisdiction, and whether you will rent or hold the license. You can book a call to map that.

How long does an embedded finance build take?

It depends on scope. A focused embedded payments integration on existing rails is a shorter effort. Embedded lending or banking with KYC, AML, and ledger reconciliation is a longer one, often measured in months rather than weeks, because the compliance and reconciliation work carries the most risk and cannot be rushed. Timelines firm up once the licensing path and the financial products are fixed.

What is the ROI of embedded finance?

ROI depends on your inputs: the transaction volume running through your platform, the margin on each financial product, the conversion lift from removing friction, and the cost of the compliance stack. We do not promise a multiple, because the return is a function of your specific economics. The way to know is to model your own volumes and take rates against the build and run cost.

Do we need a banking license to offer embedded finance?

Usually not, if you build on a Banking-as-a-Service provider that holds the license and rents its regulated capability through APIs. You take on the platform and experience layer; the provider carries the regulated activity. You may still need your own registration for certain products or scale, and in the UAE the CBUAE and the DIFC and ADGM free zones offer structured routes. The licensing decision should be made before any code is written.

How does UAE Open Finance affect embedded finance?

It is the enabling layer. The CBUAE Open Finance Regulation (Circular 3 of 2025) makes participation mandatory for licensees and supports transaction initiation, which lets a third-party platform move money from a customer’s bank account with consent. That capability, sitting on national rails like Aani, is what an embedded payment or wallet needs to function legally and at scale in the UAE. Banking-as-a-Service is the supply side of that arrangement (the licensed institution exposing capabilities through APIs); embedded finance is the demand side (the platform consuming them).

Related reading

Building financial products into your platform?

Kentro designs and engineers embedded finance into UAE and MENA platforms, from BaaS integration and KYC and AML controls to ledger reconciliation and Open Finance compliance.

Book a discovery call

How much engineering resource is needed to launch embedded finance?

A first embedded finance release usually needs a small dedicated team rather than a large one: backend engineers for the API and ledger integration, one frontend engineer for the user journey, and part time input from compliance and security. The heavier ongoing cost is not the build, it is reconciliation, dispute handling and monitoring after launch.

Which embedded finance platforms suit SME lending in the MENA region?

Platform choice in MENA is driven by licensing and local settlement rather than features. The practical questions are whether the provider is licensed in your market, whether it settles in local currency, whether it supports the identity checks your regulator expects, and whether it can report in the format your central bank requires. A platform that is strong in Europe may not clear any of these in the UAE or Saudi Arabia.

Can embedded finance include KYC and compliance out of the box?

Some providers bundle identity verification and AML screening, but bundled does not mean sufficient. In the UAE and KSA the obligation stays with the licensed entity, so the bundled checks still have to be mapped against local requirements, and screening results still need to be auditable and retained. Treat a provider's compliance module as a starting point, not as coverage.



© 2025 Kentro. Build. Secure. Scale.