What operational systems successful fintech startups use: lessons from ten companies
Starling, Monzo, Qonto, bunq, Lunar, Pleo, Tide, Ramp, Mercury and Column scaled on four operating systems. Regulators' findings show what breaks when one of them lags behind growth.
Ilia PushinPublished Oct 8, 2026·Updated Oct 8, 2026·10 min read
Short answer
Fintech startups that scale past Series A run four operational systems. A compliance workflow that grows with the customer base: onboarding controls, transaction monitoring and sanctions screening with enough people behind the alerts. A short set of operating KPIs reviewed on a fixed rhythm, such as revenue per account, cost to serve and cost-to-income. Financial controls built around one ledger of customer balances, reconciled daily against the bank, and profitability reported with and without interest income. And operations automation that removes routine work without removing the controls. Public records show the order matters. The UK regulator fined Starling £29 million and Monzo £21 million after both grew customer numbers faster than their financial crime controls, and Synapse collapsed in 2024 with a gap of tens of millions of dollars between its records and its partner banks' records. Companies such as Column, Mercury and bunq treated these systems as product, not overhead.
Key takeaways
Every regulator finding in this sample has the same shape: growth outran one operating system, usually financial crime controls or reconciliation.
Compliance capacity has to scale with onboarding volume. Starling and Monzo both added financial crime staff only after the regulator stepped in.
The companies with the clearest public KPIs report a short, fixed set: revenue per account, cost to serve, cost-to-income, net interest margin.
One ledger of customer balances, reconciled daily against the bank, is the control whose absence ended Synapse.
AI now handles most support volume at bunq, Lunar and Monzo, but the regulators judge whether alert handling and documentation stay complete.
Four systems, ten companies
After Series A, a fintech company stops being judged only on growth. Its regulator, its partner banks and its auditors start to judge whether the company can run at the size it has reached. We looked at what ten fintech companies in the UK, the EU and the US have published about how they operate: annual reports, regulator notices, court records and their own engineering and operations writing. The same four systems show up every time.
Definition
A fintech operating model is the set of systems a company uses to run its regulated business at scale: how it onboards and monitors customers, which numbers it manages by, how it controls money and books, and how it organises and automates operations.
Company
Market
Model
Public scale marker
Starling
UK
Own banking licence
£714m revenue, £223m profit before tax, FY to Mar 2025
Monzo
UK
Own banking licence
12m+ customers, £1.2bn revenue, FY to Mar 2025
Tide
UK, India
E-money licence, accounts via ClearBank
1.6m members, 14% of UK small businesses, Sep 2025
Qonto
France, EU
Payment institution, bank licence applied for in 2025
600k customers, profitable since 2023
Pleo
Denmark, EU
E-money institution
Restructured toward partnerships in 2025
bunq
Netherlands, EU
Own banking licence
€85.3m net profit, 17m users, 2024
Lunar
Denmark, Nordics
Own banking licence
Cost-to-income 1.4, H1 2025
Ramp
US
Card program with several partner banks
$1bn+ annualized revenue, Jun 2026
Mercury
US
Partner banks, OCC charter conditionally approved 2026
$650m annualized revenue, Q3 2025
Column
US
Own national bank charter
About $68m net income in 2025, FDIC data
The last two lines of the record matter as much as the first: Synapse, a US banking-as-a-service middleware company, went bankrupt in 2024, and five of the ten companies above have been fined, restricted or ordered to fix controls by their regulators. Those cases show what each system protects against.
System 1: a compliance workflow that scales with onboarding
The most expensive failures in this sample were not product failures. They were financial crime controls that grew more slowly than the customer base.
The FCA fined Starling £28,959,426 in 2024. Starling had agreed with the regulator not to open accounts for high-risk customers, then opened 49,183 such accounts anyway. Its sanctions screening had checked customers against only a fraction of the official list since 2017. The Final Notice describes a financial crime function that was under-resourced, engineering teams who built the restriction into systems without being told it existed, and committees that each received different management information, so the board had nothing it could challenge.
Monzo’s 2025 fine, £21,091,300, has the same shape. Its controls were inadequate from October 2018 to August 2020, and it then onboarded more than 34,000 high-risk customers in breach of a restriction. The FCA notes that some customers gave London landmarks as their address. According to the Final Notice, in the first half of 2019, 45% of transaction monitoring alerts were closed as “Undecided”.
The pattern repeats in the EU. In July 2024 the Banca d’Italia banned Qonto’s Italian branch from onboarding new customers over anti-money-laundering shortcomings. The Danish FSA’s 2025 inspection of Lunar’s banking-as-a-service line rated its inherent risk as high, found monitoring had been quarterly and manual, issued six orders and reprimanded Lunar for not reporting known problems on its own initiative. DNB fined bunq €2.6 million in 2025 for weak follow-up of alerts, after a 2023 court ruling had found that bunq’s AI-based screening itself was not unlawful.
What the regulators asked for afterwards is the system itself: enough trained people behind the alerts, one accountable owner for each restriction or obligation, engineering that knows which rules it is implementing, and one version of management information going to every committee. Mercury shows the other direction. Its risk and compliance team grew from nine people and a consultant to about 20% of the company, Fortune reported, and when the OCC conditionally approved its bank charter in April 2026, it required vetting of the chief risk officer, the information security officer, the BSA officer and the head of internal audit.
System 2: a short set of KPIs on a fixed rhythm
The companies with the clearest public reporting manage by a handful of operating numbers, the same ones every period. Starling reports active accounts, average revenue per account (£218.7 in FY25), cost to serve (£42.4), net interest margin (4.12%) and return on tangible equity (17.9%). Lunar’s interim report puts cost-to-income on its KPI page, down from 1.5 to 1.4, and tracks the share of income that comes from fees rather than interest, which rose from 44% to 67%. Mercury’s annual letter covers annualized revenue, customer growth, transaction volume, multi-product adoption, NPS and unit economics by audience.
Rhythm matters as much as the list. Ramp says it has tracked every day since launch, and its CEO counts the company’s age in days; leaders review the last 30 days of work to decide what to stop. Monzo built a self-serve data stack early and has since replaced a sprawling operations data model with owned data products, so customer operations managers pull their own reports instead of waiting for analysts.
A useful way to hold this together is a KPI tree: one financial goal at the top, broken into the operating numbers that drive it, each with an owner. Compliance numbers belong on the same tree. Monzo’s 45% of undecided alerts was an operating metric, and nobody acted on it in time.
System 3: financial controls around one reconciled ledger
Synapse is the case every fintech operator should read. When it went bankrupt in 2024, the court-appointed trustee, former FDIC chair Jelena McWilliams, found about $180 million held at partner banks against $265 million owed to end users. The CFPB alleged that Synapse failed to keep records of where consumer funds were held that matched the banks’ records. More than 100,000 consumers had funds frozen, and the Federal Reserve ordered Evolve, one of the partner banks, to fix its risk management for fintech partnerships.
Column, a US bank founded by a Plaid co-founder, took the opposite route: it bought a national bank in 2021, built its own ledger and connects directly to the Federal Reserve. The ledger is the system of record for every transaction. FDIC data show Column with about 150 employees and net income of about $68 million in 2025.
The second control is honest profitability reporting. Interest on deposits can carry a neobank’s results while fee revenue lags, which is why Lunar reports the fee share of its income separately and tracks cost-to-income alongside it. Pleo’s CFO wrote in 2022 that the goal was “no longer about pure growth but the efficiency of growth”, and the company slowed its expansion plan and rethought its KPIs accordingly.
System 4: operations automation with controls intact
Support and operations are where fintechs now save the most. bunq says its AI assistant handles about 97% of support activity. Lunar reports that its assistant resolves 85% of support cases and that process automation cut operating costs by 12%. Starling says AI saves 8,000 hours a month. Monzo’s Ops Agent covers more than 150 customer request types and hands off to people at defined guardrails; every message was human-reviewed at launch before moving to sampled quality checks.
Monzo also shows the risk. In 2018 it ran one customer operations agent per 19,000 customers, against a bank norm it put at one per 3,000, and aimed for one per 100,000. The same period produced the controls failures in its Final Notice. Efficiency targets for support need a matching target for the quality of onboarding data and alert handling.
Organisation design follows the same logic. Ramp puts brand and product marketing under the CTO and uses forward-deployed engineers for large-customer requests so core teams stay on the roadmap. Mercury runs cross-functional go-to-market pods with their own budgets. Pleo moved smaller customers from direct sales to self-serve and partners in 2025. Each decision sets a cost to serve per segment, which then shows up in System 2.
The minimum operating system after Series A
Compliance capacity tied to growth. Alerts per analyst and backlog age reviewed weekly, a named owner for every regulatory restriction, and the same management information going to every committee.
Five to eight operating KPIs. Revenue per account, cost to serve, cost-to-income, a retention or activity measure, and one compliance health metric, reviewed on a fixed weekly and monthly rhythm.
One ledger, reconciled daily. Customer balances reconciled against bank and safeguarding accounts every day, with breaks escalated the same day.
Profitability with and without interest income. So a rate cut does not reveal a business model problem a year too late.
Automation with human review where risk is high. Start with full review, move to sampling only when error rates are measured.
More than one banking partner, or a plan for it. Mercury moved customers off Evolve in 2025 and had to re-run KYC; portable customer data made that possible.
How we apply this
Our founder runs operations at a licensed currency exchange and cross-border payments company in Thailand, so these systems are daily work for us, not theory. For fintech clients we start with a two-week operations audit, build the KPI tree, and embed specialists who set up the compliance rhythm and reporting without building a full in-house operations team first. If you are deciding between hiring and embedding, our guide to fractional COO versus embedded operations teams covers the trade-offs, and the compliance layer under fintech marketing covers what changes on the acquisition side. To talk about your own setup, get in touch.
FAQ
What operational systems does a fintech startup need after Series A?
Four: a compliance workflow that scales with onboarding (KYC, transaction monitoring, sanctions screening and staffed alert handling), a small set of operating KPIs with a review rhythm, financial controls around a reconciled ledger, and operations automation with human review where risk is high. Each needs a named owner reporting to the board.
Why did Starling and Monzo get fined by the FCA?
Both grew faster than their financial crime controls. The FCA fined Starling £28,959,426 in 2024 after it opened accounts for 49,183 high-risk customers despite an agreed restriction, and fined Monzo £21,091,300 in 2025 for inadequate controls and for onboarding more than 34,000 high-risk customers in breach of a restriction.
What went wrong at Synapse?
Synapse, a banking-as-a-service middleware company, went bankrupt in 2024. The court-appointed trustee found about $180 million at partner banks against $265 million owed to end users, and the CFPB alleged Synapse failed to keep records that matched the banks' records of where consumer funds were held.
Which KPIs do fintech companies report?
Starling reports active accounts, average revenue per account, cost to serve, net interest margin and return on tangible equity. Lunar reports cost-to-income and fee share of income. Mercury's [annual letter](https://mercury.com/blog/inside-mercury/annual-letter-2025) covers annualized revenue, customer growth, transaction volume, multi-product adoption and NPS.
Written and reviewed by Ilia Pushin · Last reviewed Oct 8, 2026Drafted with AI assistance, edited and fact-checked by the author.This article is for general information. It is not legal, financial or medical advice.
Ilia PushinFounder, PUSHERS & COO Fintech ServiceIlia builds operating systems for growing companies in fintech and healthcare. Since 2021 he has run cross-border payments at ARBI Exchange, a licensed currency exchange in Thailand, including KYC and AML and the move into new jurisdictions.About the authorLinkedIn