Banks and financial institutions
Payment infrastructure where compliance requirements are at their highest.
Financial institutions take payments for fees, instalments and services, but every exception has to be documented and traceable.
So the focus is the audit trail, automatic reconciliation and a clear split of responsibility between you and the processor.
What you get
PCI DSS Level 1
Card data never enters your infrastructure.
Open Banking
Account-to-account payments under PSD2.
Virtual IBAN
Every incoming payment matched automatically.
Audit trail
A full log of every request and change.
AML compliance
Sanctions screening at onboarding.
Roles and access
Separate rights for finance, support and management.
Infrastructure where compliance is not optional
Financial institutions have a requirement other merchants do not: every decision has to survive inspection. Not merely work, but be provable as working to the rules, with an audit trail that stands up in front of a regulator.
That changes the priorities. In a shop the first question is how fast it starts. Here the first question is where the data is kept, who can reach it, how long it is retained and how all of that is evidenced.
So card data sits in a certified PCI DSS Level 1 environment and never passes through your infrastructure. Not because it is convenient, but because it narrows your audit scope and removes a whole class of questions you would otherwise have to answer.
Taking payments in branch and online
Institutions collect amounts too: service charges, instalments, insurance premiums, document fees, payments on consumer products.
At a counter that is an ordinary terminal, but with a requirement for reporting per member of staff and per branch, not merely per device. Reporting splits by site and by operator, which internal control needs and an inspection will ask for.
The online channel needs the same plus strong customer authentication under PSD2. There are no exemptions to be used freely here: the profile is such that any relaxation must be justified and documented.
For recurring amounts such as monthly instalments or premiums, tokenisation with recorded consent applies. The record of when and how consent was given is part of the audit trail, not a technical footnote.
An audit trail that does its job
The difference between a log and an audit trail is that the latter answers questions nobody asked in advance.
In practice that means several things. Every action in the panel leaves a record: who, when, what was changed. Every transaction can be followed from initiation to settlement, including declines and their reasons. Exports are machine-readable, not only PDF, so they can enter your own systems.
Access is by role, not shared. Counter staff see their own transactions, the branch manager sees the branch, internal control sees everything without the right to change it. That is not an extra but a baseline requirement in this sector.
A partner rather than merely a supplier
A financial institution wanting to offer payment acceptance to its own customers has two routes. Build everything itself, which is expensive and slow, or work with a processor that already has the infrastructure and the certifications.
The second makes sense when your core business is the customer relationship rather than card processing. You keep the customer and the brand while the technical and regulatory weight sits with the partner.
BulPays works as a partner of RoxPay, a European fintech with PCI DSS Level 1. That means European infrastructure behind local support, rather than a home-made solution.
The specific models of cooperation are agreed case by case, because requirements for a licensed institution differ from those for a merchant and are set by the regulator as well as by the two parties.
What to prepare before the conversation
The conversation moves faster when a few things are clear from the start.
What the use case is: collecting your own fees, a service to your customers, or both. Each leads to a different structure.
What your data residency requirements are and whether there is a geographic constraint on where data may sit.
Which systems have to connect and in what format you expect the data.
What your timelines are and whether there is an external date, a regulatory one for instance, that you are working toward.
The earlier those are stated, the less likely the design is reworked halfway through.
What narrows your audit scope
Every line here is a question you would otherwise answer to an inspector.
- Card numbers never pass through your infrastructure
- The storage environment is certified to PCI DSS Level 1
- Access is by role, with read and change separated
- Every action leaves a record of who, when and what
- Exports are machine-readable, not only PDF
- Consent for recurring amounts is recorded with date and method
Questions about this
Where is card data stored?
In a certified PCI DSS Level 1 environment on European territory. No card numbers pass through your infrastructure, which narrows your audit scope.
Is there an audit trail per member of staff?
Yes. Every action leaves a record of who, when and what, and access is by role. Exports are machine-readable so they can enter your own systems.
What does PSD2 require for the online channel?
Strong customer authentication for most payments. Exemptions exist, but at a financial institution any exemption applied has to be justified and documented.
Do you work with licensed institutions as a partner?
Yes, with models agreed case by case. Requirements for a licensed institution are set by the regulator as well, which is why the conversation starts with the use case rather than the rate.
Who stands behind the infrastructure?
BulPays is an official partner of RoxPay, a European fintech certified to PCI DSS Level 1. Support is local; the infrastructure is European.
Can reporting be split by branch and by member of staff?
Yes, and that is usually a requirement rather than a preference. The split is by site and by operator, with rights that let internal control see everything without the ability to change it.
Ready to start accepting payments?
Send us an enquiry and you will get a concrete quote with calculated fees for your business, usually within one business day.