Beyond capital and governance, the FCA’s EMI license requirements checklist calls for documented safeguarding measures, a security policy, incident reporting and business continuity procedures, and disclosure of any outsourcing arrangements. Each of these depends on a working system behind it. So, a reviewer will ask how your platform actually enforces its safeguarding measures.

