Insights · 11 min read

Banking Software Development: Scope, Compliance, and Cost

What banking software actually costs to build, why the compliance layer is the real product, and whether to build on BaaS or your own core.

By GGP Editorial

Banking Software Development: Scope, Compliance, and Cost

Banking software looks like a feature list: accounts, cards, transfers, statements. The demo always looks clean. The hard parts sit under the surface: the KYC checks you run before a customer opens an account, the ledger that has to balance to the cent every night, the audit trail a regulator will read line by line, and the license questions you answer before anyone writes code.

I write this from the vendor side. GlobeSoft is a software company founded in 2018 with 40-plus engineers and more than 300 delivered projects, and we have built trading systems, wallets, payment platforms, and financial systems for clients across a few markets. This guide covers what banking software actually is, what it costs, and what to build first.

If you are still deciding whether you need full banking software or a narrower fintech product, start with our piece on how much it costs to build a fintech app.

What "banking software" actually means

The phrase covers three different products, and they have different scopes and different buyers.

A core banking system is the ledger. Accounts, balances, transactions, interest, statements, the system of record that has to stay correct under load and audit. This is infrastructure, not a product, and it is the most expensive thing in this list to build well.

A digital banking app, or neobank, is the customer-facing layer: onboarding, accounts, cards, transfers, and support. Most of what founders mean when they say "we want to build a bank" is this layer, and in most cases it sits on top of someone else's core, not on a core you built.

A point solution is the focused version. Loan origination, KYC and sanctions screening, card issuing, treasury, payment rails, or a savings account wrapper. One job done well, sold to a bank or embedded in another product.

These overlap, but they are not the same build. A digital banking app on top of a licensed core is a six-to-twelve-month project. A core banking system built from scratch is a multi-year engineering and regulatory effort. Decide which one you are before you budget.

Build on BaaS or build your own core

This is the first real decision, and it shapes everything downstream.

Banking as a service, or BaaS, means a licensed partner owns the accounts, the ledger, the card rails, and the regulatory relationship, and exposes them through APIs. You build the customer experience on top. In the US the names you will run into are Unit, Synctera, and Treasury Prime; in Europe and the UK, Solaris, Railsr, Griffin, and Swan. For card issuing specifically, Marqueta is the name that comes up most. These are stable, real providers, and a list like this dates quickly, so check who is active when you scope the project.

Building your own core means you own the ledger, the account model, the reconciliation, and everything a licensed institution relies on. It is rarely the right first move. You build your own core when the banking infrastructure itself is the product you sell, or when you are already a licensed institution replacing legacy systems. For everyone else, a core build is years of work with no customer value until the very end.

BaaS is not risk-free, and this is worth saying plainly. One large US BaaS middle-layer collapsed in 2024, and the fintechs built on it spent months figuring out where their customers' money and account records actually lived. When you build on BaaS, your contract terms, your data access, and your exit plan are part of the product decision, not a legal afterthought. We covered the same "who owns what when it breaks" logic in fintech application architecture.

The compliance layer is the real product

Banking software is regulated software. The account screen is 10 percent of the build. The compliance layer is the other 90 percent, and it is where projects stall.

Know your customer is not optional. Every customer who opens an account has to be identified, screened against sanctions and politically exposed person lists, and monitored afterwards for suspicious transactions. In the US this means an AML program under the Bank Secrecy Act, with customer identification and suspicious activity reporting. In Europe and the UK it means a similar regime plus the consumer-protection rules that sit on top. We walked through the practical side in KYC integration for fintech.

Licensing is the question everyone tries to skip. Either you hold a license, or you operate under a partner's license. In the US, money transmitter licenses are issued state by state. In Europe, an e-money institution or payment institution license comes from a national regulator. In the UK, the FCA authorizes e-money and payment institutions. If you build on BaaS, your partner holds the license and you operate under it, which is why the partner choice matters so much.

Card data adds PCI DSS on top. If you touch card numbers at all, you inherit the card-data security standard. The short version: never store raw card data, and push card handling to a compliant processor. Our guide on fintech security requirements covers the controls in more detail.

Nothing in this section is legal advice, and the specific rules depend on where you are licensed, where your customers live, and what products you offer. The point is that compliance is a first-week topic, not a launch-week topic.

The modules that matter

The visible features are the easy ones. Here is a realistic split between what a digital banking product needs on day one and what can wait.

Must have in v1Can wait
Account opening with KYCCredit and lending
Ledger and balance (via core or BaaS)Foreign exchange
Transfers and paymentsInvestments and trading
Statements and transaction historyBusiness and multi-entity banking
Card issuing (via a partner)Multi-currency accounts
Login and authenticationRewards and budgeting tools
Admin and operations consoleAI assistants
Audit log and freeze/block controlsReal-time spend analytics

The admin console is the module nobody demos and everyone needs. When a customer says a transfer never arrived, your support team needs a screen where they can see the transaction, the state, and the rails it went over. If the console is missing, every support ticket becomes an engineering ticket.

What drives the cost

Cost in banking software is driven by four things, in rough order of impact.

Team. A digital banking build needs a product manager, a designer, two or three backend engineers, one or two mobile or frontend engineers, and usually a part-time security or compliance reviewer. Where the team sits changes the bill a lot: a senior engineer through a China-based team runs roughly $5,000 to $8,000 a month, against around $12,000 to $16,000 for the same role on a US salary. We break those numbers down in what software development costs in China.

Compliance depth. KYC vendors, sanctions screening, transaction monitoring, and the work to wire them in and test them add real time and real cost. This is the biggest hidden line item, and it scales with the number of markets you launch in.

Core decision. Building on BaaS costs less and ships faster than building your own core, but you pay the partner a fee per account and per transaction, and you inherit their constraints. Building your own core is a capital project.

Integrations. Card issuing, payment rails, KYC providers, and push notifications each add time, and each is a place where scope quietly grows.

As a rough guide, a focused digital banking MVP on top of a BaaS provider typically lands between $150,000 and $400,000. A full neobank with cards, transfers, and a couple of account products runs $500,000 to $1.5 million or more. Building your own core banking system starts well past that and runs for years. These are ranges, not quotes; the only number that matters is the one from a scoped proposal. We wrote a walk-through on getting a real number in how to estimate a custom software project.

Timeline

A focused digital banking MVP on BaaS runs six to twelve months from kickoff to a limited launch. A full neobank with cards, multiple account products, and a proper compliance stack runs twelve to eighteen months. Building your own core is a two-to-three-year program, and the honest version of that sentence is that most of the early work is invisible to customers.

Plan for a discovery phase before anyone writes code, a compliance review early enough to change the architecture, and a pilot with a small number of real customers before you open the doors. Banking products are tested in production in a way internal tools are not.

Where AI actually helps

AI has real uses in banking software, but they are narrower than the pitch decks suggest.

The useful ones are detection and text work. Fraud and anomaly detection is machine learning, not generative AI, and it has been a real part of banking for years. Document review in onboarding, where an AI pulls the name and address off an ID and flags the ones that do not match, saves genuine time. Support chatbots that answer routine questions and route the hard ones to a human work fine.

The risky ones are any place an algorithm makes a consequential decision without a human in the loop. A credit decision, a fraud hold, a compliance determination. Those need a person, and in some cases the rules require one. Keep the AI on the drafting and flagging side. If you want to understand where AI actually pays for itself in business software, start with how to add AI to existing business software.

Mistakes we see again and again

Building the app before the ledger. Founders start with the account screen because that is what a customer sees. The ledger and the reconciliation underneath it are the product. Get the money movement right first.

Underestimating compliance. KYC vendors need contracts and testing. Transaction monitoring needs rules and thresholds. This work is not a checkbox, and it does not compress.

Choosing a BaaS partner on price. The cheapest partner is rarely the one whose contract gives you clean data access and a sane exit. Ask what happens to your accounts if they fail.

Ignoring the operations console. Your support team is the first group that will tell you the product is unfinished. Build for them early.

Treating a second market as an afterthought. Adding a currency, a regulator, or a card rail later is real work if the data model assumed one of each.

Frequently asked questions

How much does banking software cost to build?

A focused digital banking MVP on a BaaS provider typically lands between $150,000 and $400,000. A full neobank runs $500,000 to $1.5 million or more. Building your own core starts past that and runs for years. See where the money goes in a custom build for the full breakdown.

Do I need a banking license to launch?

Not necessarily. Many digital banking products operate under a BaaS partner's license. You either hold a license, or you operate under a partner's license. The specific requirement depends on your product, your market, and where your customers live.

Should I build on BaaS or build my own core?

Build on BaaS unless the banking infrastructure itself is the product you sell, or you are already a licensed institution replacing legacy systems. Building your own core is a multi-year capital project with no customer value until the end.

How long does it take to build a digital banking app?

Six to twelve months for a focused MVP on BaaS, twelve to eighteen for a full neobank. Your own core is a two-to-three-year program.

What compliance do I need on day one?

KYC and sanctions screening, an AML program, transaction monitoring, and PCI DSS if you touch card data. The exact list depends on your license and your markets. Start with KYC integration for fintech.

Can I start with a single product?

Yes, and you should. A savings account wrapper, a single card product, or a focused payment product is a faster path to real customers than a full banking suite. The trimming logic in how to build a SaaS MVP applies here too.

Who we are

GlobeSoft is a software development company founded in 2018, with 40-plus engineers and more than 300 delivered projects for over 100 clients across the US, Brazil, South Africa, and Singapore. We build custom software, mobile apps, SaaS platforms, FinTech systems, ERP and CRM, and AI products on a stack that includes Java, Spring Boot, Go, Python, React, Vue, and Node.

If you are planning a digital banking product, a payment platform, or a financial system of any kind, talk to us about your project. Send us the rough idea and we will help you figure out the core decision, the compliance scope, and what to build first.

Need help applying this?

Tell us what you are building and where you are today. We typically reply within 24 hours.