The email says the firm has been accepted into a regulator's sandbox cohort. Within a week the website says "regulated by" and the ad copy says "licensed". Both are wrong, and the correction usually arrives from a compliance officer at a bank rather than from the regulator.
A sandbox is a supervised testing arrangement. The regulator lets a firm run a defined activity, with a defined group of customers, for a defined period, under conditions written specifically for that test. Some sandboxes work through a restricted or limited authorisation. Others work through waivers, no-action style comfort or individual guidance attached to an existing permission. The mechanics differ by country, and the difference matters, because what the firm ends up holding is either a narrow permission or no permission at all.
What admission actually buys you
The real product of a sandbox is supervisory attention. A named contact at the regulator, a schedule of check-ins, and a chance to argue about how existing rules apply to a model that predates none of them. For a firm doing something genuinely new around settlement, tokenised instruments or automated advice, that access is worth more than any marketing line. For a firm that wants to sell contracts for difference to retail clients using a model the regulator has supervised since the 1990s, there is nothing to test, and applications in that shape are usually turned away.
The second thing admission buys is a documented conversation. When the firm later files a full application, the file already contains a business description the regulator has read, a risk assessment it has commented on, and evidence of how the firm behaved under observation. That shortens argument later. It does not shorten the application itself. See how licence timelines actually run for why the calendar rarely compresses.
The limits are the point
Sandbox conditions are written to cap harm. Typical shapes include a maximum number of retail customers, a cap on exposure per customer, a requirement that customers are told they are part of a test, mandatory disclosure of what protection does and does not apply, and an end date. Some conditions require the firm to hold funds with a third party or to avoid holding client money at all.
Those limits describe the business you can run. A firm whose unit economics only work at scale cannot prove them inside a customer cap. That is a reason to plan the sandbox as a technical and supervisory proof, not as a revenue phase.
Sandbox exit is not automatic. Leaving the cohort with a positive report does not convert into full authorisation. The firm still applies, still meets capital and systems conditions, and still faces fit and proper assessment of its people. Take your own legal advice on what your specific admission grants.
How third parties read sandbox status
This is where sandbox firms get surprised. Banks, payment service providers, acquirers, liquidity providers and platform vendors all run their own onboarding checks, and none of them are bound by the regulator's view.
A bank's onboarding team asks a narrow question: what permission does this entity hold, in which register, with which reference number, and does the activity we are asked to bank fall inside it. A restricted authorisation with a register entry answers that question, though the conditions attached will be read closely. A sandbox arrangement with no register entry does not answer it at all, and the file usually stalls in the same place as any unlicensed applicant. The mechanics behind that are in why banks refuse brokers and in correspondent banking de-risking, which is the pressure that makes onboarding teams conservative.
Card acquirers add a second layer. Underwriting looks at the merchant category, the expected chargeback profile, the refund policy and the entity's regulatory standing in the country where cardholders live. A test cohort with a hard end date reads as a business with a hard end date, which is a poor fit for a rolling merchant agreement and a rolling reserve.
Platform vendors and liquidity providers ask a different question again: who carries the regulatory risk if the flow turns out to be retail clients in a country neither party is allowed to serve. Their counterparty checks are described in what platform vendors verify before they connect you.
App stores and ad platforms
Mobile stores and the large ad networks operate published policies for financial products. Both families of policy tend to work the same way: the publisher or advertiser names a jurisdiction, names the entity, and supplies a licence reference that a reviewer can check against a public register. Some categories also require a certification step before financial ads can run at all.
A sandbox conditional permission with a register entry gives a reviewer something to check. A sandbox letter does not. That is not a judgement about the firm, it is a consequence of review processes built around registers. If your acquisition plan depends on paid distribution, treat register visibility as a hard dependency and check the current policy text yourself before you build the funnel.
When the sandbox is the right move
Three cases justify it. The model genuinely does not map onto existing rules and you need the regulator to say how it does. The firm needs supervised proof before a larger partner will commit. Or the jurisdiction runs a pathway where sandbox completion feeds directly into a specific authorisation route, in which case the sequence is part of the licence plan rather than a substitute for it.
Everything else is a delay. A firm selling a well understood product to retail clients in a supervised market should apply for the permission that product needs, budget for it honestly, and read how regulators test business model fit before writing a word of the application. And whichever route you pick, the wording on your website has to match the permission you hold, because supervisors read marketing copy and so do the banks.
"A sandbox letter opens doors at the regulator and almost none at the bank. If your plan needs a merchant account in month two, plan for the register entry, not the cohort."
— Alex Onta, Executive Director, SINGUARD
Key Takeaways
- A sandbox is a supervised test with caps on customers, exposure and duration, not authorisation to trade at scale.
- Some sandboxes run on a restricted authorisation with a register entry, others on waivers or guidance with none. Check which one you would hold.
- Banks, acquirers, platform vendors and ad reviewers check registers, so a sandbox letter without a register entry rarely clears onboarding.
- Completing a sandbox does not convert into a full licence. You still file the application and meet every condition.
Frequently Asked Questions
Does a sandbox let me take retail clients?
Usually only a capped number, with disclosure that they are part of a supervised test and with limits on exposure. The conditions are written per firm, so read yours and take legal advice on what it permits.
Can I say my firm is regulated during a sandbox?
Only if you hold an actual permission on a public register, and then only in the exact terms of that permission. Describing a test arrangement as a licence is the kind of statement supervisors act on.
Will a sandbox make my licence application faster?
It can make the substance of the application easier to argue because the regulator has already read your model. It does not remove any application stage, capital condition or approval step.
About the Author
Alex Onta is an Executive Director at SINGUARD. He built eTrader, the terminal, the mobile apps, eTrader Broker, Copytrading, Business and Community, along with the worldwide clustered-server infrastructure it all runs on, with his brother Roman Onta helping on the design, and he leads that division today. Together with Roman he builds the Prop Firm CRM, the Broker CRM, Scalegram and CopySignals, and the two of them carry worldwide compliance, payment processing and international business structuring side by side. He lives and works in Dubai for most of the year. Meet the executive duo leading Singuard's five divisions.