On this page
In brief
- Wallet as a Service helps UAE businesses launch digital wallets without building ledger, payment and operational infrastructure from scratch.
- UAE licensing requirements depend on the actual fund flow, control of customer money and regulated activities, not simply on the wallet product label.
- Providers should be compared on compliance, safeguarding, wallet capabilities, APIs, ledger reliability, security, pricing and implementation requirements.
- The right embedded wallet model should match the specific use case, whether payments, refunds, loyalty, marketplace payouts, payroll or international transfers.
This guide explains how WaaS and embedded wallets work, the main UAE licensing and compliance considerations, available operating models, pricing structures and provider-selection criteria for banks, fintechs, marketplaces, retailers, telecom operators, payroll providers and technology companies.
What Are Wallet as a Service and Embedded Wallets?
Wallet-as-a-Service and Embedded-Wallet Definitions
Wallet as a Service (WaaS) is infrastructure that enables a business to create and operate digital wallets through APIs, configurable platforms or white-label applications. Depending on the provider, the service may include customer onboarding, wallet creation, ledger management, funding, payments, transfers, payouts, compliance controls, reporting and reconciliation.
An embedded wallet is the customer-facing wallet functionality integrated directly into another product, such as a marketplace, retailer application, telecom service or SaaS platform. WaaS therefore describes the underlying infrastructure and service model, while an embedded wallet describes how that functionality is incorporated into the customer experience.
Wallet models can differ significantly. A closed-loop wallet may restrict value to a retailer or defined network, while other wallets can support redeemable balances, external transfers, card payments or payouts. Businesses should also distinguish stored-value and payment wallets from self-custody cryptocurrency wallets and simple card-tokenisation functionality.
Is Wallet as a Service the Same as Banking as a Service?
No. Wallet as a Service primarily provides infrastructure for maintaining balances and enabling wallet-related transactions. Banking as a Service can cover a wider range of financial products, including payment accounts, cards and other banking or financial services.
WaaS also differs from a payment gateway, which primarily helps merchants accept payments, and from payment orchestration, which routes transactions between multiple payment providers. A wallet typically maintains an ongoing balance or value relationship with the user rather than processing only an individual payment.
Define the Wallet Model Before Comparing Providers
Map the Use Case and Fund Flow
Start by documenting exactly what the wallet must do. Define who will use it, which currencies it will support, how users will add funds, where money can be spent or transferred and whether withdrawals or redemption are permitted.
Then map the complete fund flow between customers, merchants, the wallet provider, banks, card schemes and payout or remittance partners. Determine which entity receives and controls customer money, which system records the balance and which party maintains the contractual relationship with the end user.
These details affect both technology requirements and regulatory classification. A retailer offering restricted store credit, for example, can have very different requirements from a platform allowing users to hold transferable funds and send them to external beneficiaries.
Choose the Delivery and Operating Model
WaaS providers can offer API-only infrastructure, managed wallet programmes or complete white-label applications.
With API infrastructure, the client generally controls more of the user experience and integration but also needs greater internal engineering and operational capability. Managed models may combine technology with compliance processes, payment connections and operational support. White-label models can additionally provide ready-made mobile or web applications under the client's brand.
The provider's legal role is equally important. It may act as a regulated operator, programme manager, integrator working with licensed partners or technology supplier only.
Create a responsibility matrix covering onboarding, KYC and KYB, transaction monitoring, safeguarding, fraud controls, reconciliation, customer service, reporting, application ownership, hosting and access to wallet data before selecting a model.
UAE Licensing, Compliance and Fund Protection
Does an Embedded-Wallet Business Need a UAE Licence?
There is no single UAE licence called an “embedded-wallet licence”. Regulatory requirements depend on the activities being performed, who receives or controls customer funds and how value can be used, transferred or redeemed.
For UAE activities outside the Financial Free Zones, businesses should assess their proposed model against the Central Bank of the UAE regulatory framework. Depending on the structure, the Stored Value Facilities Regulation and the Retail Payment Services and Card Schemes Regulation can be relevant. The latter covers regulated retail payment activities including payment account issuance, payment instruments and domestic and cross-border fund transfers.
The CBUAE continues to list Stored Value Facilities and Retail Payment Services among regulated activities, while the current Central Bank legal framework gives it authority over stored value facilities, retail payment systems and related digital financial services.
Businesses should therefore verify the exact UAE entity supporting the product, its authorised activities, geographical scope and dependence on sponsor banks or other regulated partners.
Working with a licensed WaaS provider does not necessarily transfer every regulatory responsibility away from the client. Responsibilities can remain around customer communications, data, outsourcing, operational controls and activities performed directly by the client.
Similarly, an authorisation obtained in a financial free zone such as DIFC or ADGM does not by itself grant permission to perform all regulated activities elsewhere in the UAE. The proposed structure should be reviewed by qualified UAE legal and compliance professionals before launch.
KYC, KYB, AML and Sanctions Responsibilities
Evaluate how the provider performs individual and business verification, beneficial-owner checks, sanctions screening and transaction monitoring.
The operating model should support risk-based onboarding, configurable limits, ongoing customer due diligence and investigation or escalation of unusual transactions. CBUAE payment-sector requirements place AML/CFT obligations on regulated payment service providers and stored-value providers, including risk assessment and suspicious-transaction reporting.
The contract and operating procedures should identify which party makes compliance decisions, retains evidence, investigates alerts and submits regulatory reports.
Safeguarding and Consumer Protection
A critical due-diligence question is where wallet funds are held and how they are protected from the provider's operating funds and creditors.
Under the UAE SVF framework, licensees must maintain mechanisms for protecting the float, maintain sufficient funds for redemption and perform regular reconciliation; the regulation specifies at least daily reconciliation between system records and the actual float.
Also review redemption terms, settlement procedures, refunds, complaints, disputed transactions, wallet freezes and treatment of inactive or dormant balances. These operational details can materially affect both customer experience and financial risk.
Data Protection, Outsourcing and Cybersecurity
Wallet implementation can involve identity documents, transaction histories, financial records and behavioural data. Providers should therefore be evaluated against applicable UAE data-protection rules and any regulatory requirements relating to outsourcing, cloud infrastructure and cross-border transfers.
The UAE Personal Data Protection framework includes specific conditions for transferring personal data outside the country, including rules for destinations with and without an adequate level of protection.
Review encryption, strong authentication, privileged access, audit logs, data retention and key-management practices. Where cardholder data is handled, establish the applicable PCI DSS scope.
The due-diligence process should also cover penetration testing, vulnerability management, incident response, business continuity, disaster recovery, recovery objectives and notification responsibilities. Record responsibilities across the client, WaaS provider, regulated partner and material subcontractors.
How to Compare Wallet-as-a-Service Providers
Wallet Features and Payment Coverage
Compare providers against the actual customer journeys rather than the length of the feature list. Relevant capabilities can include card or bank top-ups, withdrawals, peer-to-peer transfers, merchant payments, payouts, refunds, loyalty balances, virtual or physical cards and FX.
Check whether the platform supports consumer and business wallets, multiple currencies, sub-wallets and configurable balance or transaction limits.
Also verify available banking rails, card schemes, payout methods, markets and cash-in or cash-out options. Test how the system manages declines, reversals, chargebacks and failed transactions.
Can an Embedded Wallet Support International Transfers?
Yes, but an API feature alone does not make international transfers operationally or legally available.
Verify whether the proposed model includes the necessary cross-border transfer capabilities, regulated entities, FX arrangements and payout partners. Compare supported countries, currencies, corridors, settlement times, transaction limits and total transfer costs.
International wallet use cases also increase the importance of beneficiary screening, sanctions controls, source-of-funds procedures and end-to-end transaction traceability.
APIs, Architecture and Integration Quality
Review APIs for customer onboarding, wallet creation, KYC, funding, payments, payouts, refunds, transfers, balances and reporting.
Technical due diligence should cover authentication, idempotency, webhook reliability, rate limits, API versioning and error handling. Developers should test the sandbox rather than relying exclusively on documentation.
Assess SDKs, sample code and support for web, mobile and backend integration. Also identify third-party dependencies and determine whether development, sandbox and production environments are adequately separated.
Ledger, Reconciliation, Fraud and Reliability
Establish which ledger is the authoritative source of truth for wallet balances. Review whether transactions post in real time and how reversals, adjustments and settlement events are represented.
Providers should offer sufficient audit trails, reconciliation reports and transaction exports for finance and operations teams to investigate discrepancies.
Fraud controls can include configurable rules, transaction and velocity limits, device signals, account restrictions and manual-review workflows.
For reliability, compare uptime commitments, processing latency, capacity limits, maintenance procedures, disaster-recovery arrangements and recovery objectives. Ensure that wallet balances and transaction histories can be exported if the business later changes providers.
Provider Strength and Operational Support
Technology should be considered alongside operational capability. Assess the provider's financial stability, UAE experience, regulated relationships and history of implementing comparable programmes.
Review compliance operations, administrative dashboards, reporting tools and customer-service functionality. Contractual SLAs should define incident severity, escalation routes, support availability and communication during outages or material changes.
Build a Weighted Provider Scorecard
A weighted scorecard helps teams compare providers consistently and document the evidence behind each decision. Scores should not override mandatory requirements: if a provider cannot legally support the proposed UAE activity, a high technology or pricing score cannot compensate for that limitation.
UAE Wallet-as-a-Service Provider Evaluation Scorecard
Evaluation criterion | Weight | Evidence to review | Provider score (1–5) | Weighted score |
UAE licensing and regulated partners | 20% | Licensed entity, authorised activities, geographic coverage and reliance on sponsor banks or payment partners | — | — |
Compliance and safeguarding model | 15% | KYC/KYB, AML, sanctions screening, transaction monitoring, fund segregation, reconciliation and reporting responsibilities | — | — |
Wallet capabilities and payment coverage | 12% | Wallet types, currencies, top-ups, payments, transfers, payouts, refunds, cards, FX and international corridors | — | — |
APIs and white-label capabilities | 10% | API coverage, documentation, sandbox, SDKs, webhooks, idempotency, versioning and branding options | — | — |
Ledger, reconciliation and fraud controls | 10% | Real-time ledger, reversals, audit trails, settlement reports, fraud rules, velocity controls and manual review | — | — |
Security and resilience | 10% | Encryption, access controls, PCI DSS scope, penetration testing, incident response, disaster recovery and recovery objectives | — | — |
SLAs and operational support | 8% | Uptime, processing latency, support hours, escalation procedures, dashboards and change notifications | — | — |
Pricing and minimum commitments | 7% | Setup fees, platform charges, per-wallet and transaction fees, FX margins, reserves and third-party costs | — | — |
Implementation effort and timeline | 4% | Integration resources, regulatory dependencies, customisation, testing, training and production-launch requirements | — | — |
Contract, portability and exit terms | 4% | Audit rights, liability, subcontractors, data ownership, transaction-history export, migration support and termination fees | — | — |
Total | 100% | Weighted score = criterion weight × provider score ÷ 5 | — | — / 100 |
The weights can be adjusted to the specific wallet model. However, missing UAE permissions required for the intended activity should be treated as an exclusion criterion regardless of the provider's total score.
Match Provider Capabilities to the Use Case
Different businesses require different wallet infrastructure.
Platforms and marketplaces should prioritise sub-ledgers, seller onboarding, split payments, commission management, refunds and scheduled payouts.
Retailers and e-commerce businesses may need branded wallets, instant refunds, cashback, gift balances and loyalty integrations. They should clearly distinguish restricted closed-loop value from balances that customers can redeem or transfer externally.
Banks, fintechs and regulated institutions should focus on regulatory accountability, integration with core systems, outsourcing controls, governance and configurable compliance workflows.
Telecom operators may require white-label mobile applications, airtime and bill payments, agent networks, cash-in and cash-out and infrastructure capable of supporting large transaction volumes.
Payroll and remittance providers should assess salary disbursement, beneficiary wallets, FX, international corridors and payout options. Where UAE wage distribution is involved, Wages Protection System requirements must also be considered. CBUAE approval and additional participation requirements apply to payment service providers seeking WPS access.
SaaS and technology companies may use embedded wallets for balances, billing credits, collections or payouts but should structure the fund flow carefully to avoid unintentionally assuming responsibility for regulated customer funds.
For every use case, scenario-based demonstrations should cover successful transactions as well as failed payments, refunds, disputes, frozen wallets and reconciliation exceptions.
Wallet-as-a-Service Pricing and Total Cost
Common Pricing Components
WaaS pricing can combine several charges rather than a single transaction fee. Common components include setup and integration fees, platform subscriptions, monthly minimum commitments and per-wallet charges.
Providers can also charge separately for customer onboarding, KYC or KYB, top-ups, payments, transfers, withdrawals, payouts and refunds. Programmes involving cards may have issuing and processing fees, while international services can include FX spreads and cross-border partner charges.
Compliance support, reporting, premium support, reserves and revenue-sharing arrangements can further change the economics of the programme.
Calculate Total Cost of Ownership
Compare providers using expected operating scenarios rather than published headline prices.
Model the expected number of active wallets, onboarding volumes, transaction frequency, payment methods, currencies and international corridors. Include internal engineering, compliance, reconciliation, fraud-management and customer-support costs.
Ask providers to disclose volume tiers, chargeback expenses, taxes, third-party pass-through costs and any reserve or collateral requirements.
Where safeguarded customer funds can generate interest or other economic benefits, clarify contractually which party is entitled to them.
Finally, include termination, data-export and migration costs so that a lower initial price does not hide an expensive future exit.
Provider Due Diligence and Implementation
Questions to Include in the RFP
A provider RFP should require precise answers to several fundamental questions:
- Which UAE legal entity and regulatory permissions support the proposed wallet activities?
- Who receives, holds and safeguards customer funds?
- Which regulatory and operational responsibilities remain with the client?
- Which functions depend on banks, card schemes, payment processors or other subcontractors?
- What internal engineering, compliance and operational resources must the client provide?
- How are outages, regulatory changes, subcontractor changes and provider exit managed?
Request documentary evidence wherever possible rather than accepting high-level claims.
Test the Provider Before Selection
Complete regulatory, financial, information-security and operational due diligence before signing a long-term agreement.
A proof of concept should cover onboarding, wallet creation, funding, payments, transfers, refunds, transaction failures and reconciliation. Compare sandbox behaviour with documented production capabilities and identify features that are simulated or unavailable in production.
Test transaction limits, administrative reporting, exception management and support responsiveness. For higher-risk or larger implementations, request references from customers operating comparable UAE programmes.
How Long Does Wallet Implementation Take?
There is no standard WaaS implementation period. The schedule depends on whether the necessary regulatory structure already exists, the complexity of KYC processes, API integration, application customisation and connections to banks, schemes or payout partners.
Projects can also require contracting, information-security assessments, operational design, user acceptance testing, training and, for mobile applications, app-store review.
Providers should therefore supply a milestone-based implementation plan showing all external dependencies, client responsibilities and regulatory or partner approvals that could affect launch.
Follow a Controlled Launch Process
A structured rollout reduces regulatory, operational and customer-experience risk:
- Finalise customer journeys, wallet functionality, fund flows and compliance responsibilities.
- Compare shortlisted providers using the weighted evaluation scorecard.
- Agree pricing, SLAs, audit rights, liability allocation, incident procedures and exit support.
- Complete integrations, required approvals, data migration, testing and operational training.
- Launch a controlled pilot using defined commercial, operational, compliance and risk metrics.
- Expand the wallet only after resolving material reconciliation, compliance and customer-support issues.
The right Wallet-as-a-Service provider is therefore not simply the platform with the most features. The strongest fit is the provider whose regulatory model, fund-protection arrangements, wallet functionality, APIs, operational controls, economics and implementation requirements match the specific way the business intends to serve customers in the UAE.