Background Mobile

Card Issuing Through Transact Payments: 12 Months to a Regulated Launch

backend development/
September 17, 2026
Card Issuing Through Transact Payments: 12 Months to a Regulated Launch

A practical account of what it actually takes to go from idea to issued card using Transact Payments as your programme manager — licences, timelines, integration work, and the decisions that will slow you down if you get them wrong.

What Transact Payments Actually Does in Your Stack

Transact Payments Limited (TPL) is an FCA- and MFSA-regulated e-money institution. When you build a card programme through them, they act as the programme manager: they hold the e-money licence, sit between you and Mastercard or Visa, and take on the regulatory relationship you would otherwise spend years building yourself.

That is the core trade-off. You give up some control over the BIN range, some flexibility in processor choice, and you pay a per-transaction margin on top of interchange. In return, you get to skip the three to five years it typically takes to obtain your own EMI licence in the UK or EU, and you sidestep the capital requirements that come with it (the FCA requires a minimum of €350,000 in own funds for a full EMI authorisation).

For most Series A or Series B fintechs, that is the right call. You validate the product first. If you need your own licence later, you pursue it with real transaction data in hand.

TPL issues cards on Mastercard rails. Your users get physical or virtual Mastercard debit or prepaid cards. The programme sits under TPL's BIN sponsorship, which means scheme rules, disputes, and chargebacks flow through their operations team. You need to understand what that means for your support model before you sign anything.

What Does the 12-Month Timeline Actually Look Like?

Twelve months is realistic if you start with a clear product spec and a development team that has done API integrations before. It is not a marketing number. Here is roughly how it breaks down.

Months 1–2: Contracting and programme design

TPL requires a formal programme application. This covers your use case, expected transaction volumes, target geography, AML/KYC approach, and business model. They will ask for a compliance framework document. If you do not have a MLRO appointed, that will block you. Budget two to four weeks just for legal review of the Programme Agreement.

Months 3–4: Sandbox integration

TPL exposes a REST API for card management, account creation, and transaction processing. The sandbox environment is reasonably stable. Core endpoints you will integrate early: account creation, card issuance (virtual first), balance enquiry, and transaction history. TPL uses ISO 8583 messaging internally; your API surface is JSON over HTTPS, so you are not dealing with raw financial messaging unless you want to.

KYC is your responsibility at the application layer. TPL mandates standards-compliant identity verification but does not prescribe the vendor. Most teams use Onfido, Sumsub, or Jumio. Whichever you pick, build the webhook pipeline carefully. A failed KYC that does not correctly block card activation is a compliance incident.

Months 5–8: Build and compliance sign-off

This is the longest phase and the one most teams underestimate. TPL's compliance team will review your KYC flow, your transaction monitoring configuration, and your customer-facing terms before they move you to production. Expect two to three review cycles. Each cycle can take two to four weeks.

Transaction monitoring deserves specific attention. You need rule-based alerts for structuring, velocity breaches, and high-risk merchant categories. If you are building on a modern stack, something like Sardine or Unit21 integrates without massive lift. If you are rolling your own rules engine, document everything, because TPL will ask for it.

Months 9–10: Physical card production and fulfilment

TPL works with card manufacturers on their approved list. Lead times for physical card stock run eight to twelve weeks. Do not start this process late. You need to finalise card artwork, agree embossing/print specs, and get the design approved by both TPL and Mastercard. Mastercard's brand guidelines are specific. A logo in the wrong position sends you back a week.

Months 11–12: Soft launch and scale

A controlled rollout to a limited user cohort, monitoring fraud rates, dispute rates, and support load. TPL's chargeback SLA is 45 days from transaction date for Mastercard disputes. Make sure your operations team knows the retrieval request workflow before you hit volume.

/// Not sure where to start?

Get the architecture before you commit

Tell us what you're building and we'll map the technical approach, stack, and rough timeline. No cost, no obligation, no sales call required.

How Should You Structure the Technical Integration?

Build an abstraction layer over TPL's API from day one. Not because TPL is unreliable, but because programme managers change, licence arrangements shift, and you do not want a future migration to touch every service in your backend.

A thin card service that owns all TPL interactions, exposes your own internal API, and emits domain events to a message broker (Kafka works well here) gives you that insulation. Downstream services, notifications, reporting, ledger updates, consume from the broker. If you swap TPL for another programme manager in three years, you rewrite one service.

On the ledger side, you need to decide early whether you are running a shadow ledger or trusting TPL's balance as your source of truth. Running a shadow ledger adds engineering overhead but gives you real-time balance display without a round-trip to TPL's API, and it gives you an audit trail you control. For regulated use cases, it is almost always worth the overhead.

Webhooks and Idempotency

TPL fires webhooks for transaction authorisations, settlements, card status changes, and KYC outcomes. Your handler must be idempotent. Webhooks can arrive out of order and can be retried. Store the event ID, deduplicate on ingest, and process asynchronously. Do not process synchronously inside the HTTP handler; you will create race conditions under load.

What Are the Costs You Should Model Before Signing?

Pricing varies by programme and volume, but here is the shape of what you are paying for.

Cost Item Typical Range
Programme setup fee £20,000–£50,000 one-time
Monthly platform fee £2,000–£8,000 depending on volume tier
Per-card issuance (virtual) £0.10–£0.50
Per-card issuance (physical) £3.00–£7.00 including fulfilment
Per-transaction fee £0.05–£0.20
FX margin (non-GBP) 0.5%–2.0% over interbank

These are indicative. Actual figures depend on your volume commitments and geography. TPL is more competitive on volume above 50,000 active cards.

The number teams consistently underestimate is the compliance overhead, not the fee, but the internal headcount. You need someone who owns the relationship with TPL's compliance team. That is a real role, not a hat someone wears.

Conclusion

A card programme through Transact Payments is achievable in twelve months if the contracting, KYC integration, and compliance review cycles are treated as first-class engineering and product work, not afterthoughts.

The decision to use a programme manager versus pursuing your own EMI licence is largely a question of where you are in your growth curve. If you do not have 24 months of runway and a compliance team already in place, the programme manager route is the right one.

If you are scoping a card programme and want a technical review of your integration architecture or compliance workflow before you commit to a vendor, talk to us. We have built on TPL and other programme manager stacks and can give you an honest read on where the risk sits in your specific design.


FAQ

How long does it take to get a physical card into a user's hands after account approval?

After your programme is live, a newly approved user can have a virtual card in minutes. Physical card delivery runs five to ten business days depending on your fulfilment partner and geography. The longer lead time is in the pre-launch phase: card stock manufacturing takes eight to twelve weeks and needs to be started well before your go-live date.

Does using Transact Payments prevent us from getting our own EMI licence later?

No. Running under TPL's licence and applying for your own are independent tracks. Many fintechs operate under a programme manager for two to three years, build a transaction history, and then use that evidence to support an FCA or Central Bank of Ireland application. The application process is easier with real data than without it.

Who handles Mastercard chargebacks and disputes?

TPL's operations team manages the scheme-level dispute process. You are responsible for providing evidence (transaction records, KYC data, communications) within the timeframes TPL specifies. Mastercard's standard chargeback window is 120 days from transaction date, but TPL's internal SLA for evidence submission is typically shorter. Build your dispute workflow before you go live.

Can we issue cards in multiple currencies?

TPL supports multi-currency accounts. Users can hold balances in GBP, EUR, and USD at minimum, with FX conversion handled at point of transaction or on transfer depending on your programme configuration. You configure which currencies are available per account type. FX margin is a revenue line some fintechs keep, others pass through to users.

What happens if Transact Payments loses its licence or exits the market?

This is a real operational risk. TPL holds the e-money licence, so if it were revoked, your programme would be suspended. You should have a documented migration plan for an alternative programme manager. Keep your integration behind an abstraction layer, maintain your own customer data and transaction history, and review TPL's financial health as part of your annual vendor due diligence. The risk is low but not zero.

Have a project in mind? Contact Sodio Technologies to discuss your requirements and explore the right technology solution for your business.

/// Work with us

Talk to the engineers who'd build it

You'll get a technical scope, timeline and cost estimate from the people doing the work, not an account manager. In-house team, no subcontracting, since 2016.

Contact Us