The model started at the Financial Conduct Authority in the United Kingdom and spread quickly. Singapore, Abu Dhabi, Dubai, Hong Kong, Australia, Canada and a long list of others now run some version of it, and the European Union has built supervised testing arrangements into its own framework for distributed ledger market infrastructure and into the artificial intelligence rules. The label varies. The structure is broadly the same.
A firm applies with a defined proposition. If accepted it runs a limited live test: a capped number of customers, capped exposure, a fixed duration, agreed safeguards, and reporting to a named supervisor throughout. At the end there is a report and a decision about what happens next. That is the whole mechanism, and most of the confusion around sandboxes comes from expecting it to be something else.
What a place actually gives you
Four things, in descending order of value.
A named contact at the regulator who has read your file. For a small firm this is the genuine prize. Instead of submitting a full authorisation application and waiting months to discover that the supervisor reads a key definition differently, you get to ask.
Restricted permissions or individual guidance that let the test run legally without full authorisation. The form differs by jurisdiction. Some regulators issue a restricted authorisation, some grant waivers or modifications of specific rules where the law allows it, some issue a bespoke testing licence such as the innovation arrangements at the Dubai and Abu Dhabi authorities. What no regulator does is disapply legislation. Anti-money laundering obligations, sanctions rules and data protection apply in a sandbox exactly as they do outside one.
Evidence. A completed test produces real customer data, real error rates, real complaint volumes and a documented control environment. That evidence goes into the full application afterwards and answers questions the regulator would otherwise have to ask hypothetically.
Signalling, which matters commercially and is the part most often oversold. Being in a cohort is useful when talking to banking partners and investors. It is not an endorsement of the product, and most regulators say so explicitly in their published material.
What it does not give you
Not a licence. This is the misunderstanding that costs firms the most. Exiting a sandbox successfully means you may now apply for authorisation through the normal route, with the normal capital, governance, fitness and controls requirements. The distinction between a permission to operate and a lighter registration is set out in licence versus registration, and neither of them is what a testing place is.
Not passporting. A test authorised in one country stays in that country. An EU firm testing under a national arrangement cannot serve customers in other member states on that basis, since passporting attaches to full authorisation.
Not a faster path in every case. Sandbox cohorts run to a published calendar with application windows, assessment, a test period often measured in months, then the substantive application. For a firm with a clear model and the capital ready, applying directly can be quicker, and the realistic timings are in the licence application timeline.
Describing a firm as sandbox approved or regulator backed in marketing is where sandbox participation turns into a compliance problem. Several regulators have published warnings about exactly this wording, and the restriction usually appears in the test conditions themselves.
Who gets accepted
Admission criteria are published and similar across jurisdictions. The proposition has to be genuinely innovative rather than a repackaging of an existing service. It has to be intended for the regulator's own market. There has to be a clear consumer benefit. The firm has to demonstrate a real need to test in a live environment rather than in-house. And it has to be ready, with a working product, a testing plan, defined success measures and an exit strategy for customers if the test stops.
That last requirement fails more applications than anything else. Firms apply with a slide deck and a prototype, and the regulator is looking for something that can take real money from a real customer next quarter under supervision.
Most regulators also run an innovation hub or advice service alongside the sandbox, which is open all year, requires no cohort place and answers the question many firms actually have, which is whether their model needs authorisation at all. For a payment or trading business that question often resolves into an electronic money institution permission, a payment services authorisation, or a crypto registration under the European crypto framework. Asking the hub costs nothing and takes weeks rather than a cohort cycle.
Where sandboxes matter most
They are most useful where the law is genuinely unclear about a new structure, which in practice means tokenised assets and settlement, artificial intelligence in credit and advice decisions, open banking data models, and identity and verification technology. In those areas a supervisor's written view is worth more than any legal opinion you can buy, because the supervisor is the one who will later decide.
They are least useful for a business model the regulator already understands. A firm setting up a brokerage, a payment operation or a prop trading business is not doing anything novel from a supervisory point of view. There is an established authorisation route, published requirements and a known assessment process. Applying for a testing place there is applying for permission to test something nobody has asked a question about, and the time is better spent on the application itself, on capital requirements and on building the compliance function that the authorisation will require anyway.
SINGUARD builds software for firms that go through those processes, which means we see the same pattern from the other side: the technology is rarely what holds an application up. Governance documents, source of funds evidence for the shareholders, and a compliance officer the regulator will accept are what decide the timeline.
"A sandbox tells you whether the regulator understands what you are building. It does not tell you that you can sell it next year, and firms that confuse those two things burn a year finding out."
— Roman Onta, Executive Director, SINGUARD
Key Takeaways
- A sandbox place is a supervised live test with capped customers, capped exposure and a fixed duration, not an authorisation to operate.
- Anti-money laundering, sanctions and data protection obligations apply inside a sandbox exactly as they do outside it.
- The most valuable output is a named supervisory contact and documented evidence that feeds the full authorisation application afterwards.
- For established models such as brokerage or payments, applying directly for authorisation is usually faster than waiting for a cohort cycle.
Frequently Asked Questions
Does completing a regulatory sandbox mean a firm is licensed?
No. Completing a test means the firm may then apply for full authorisation through the standard route, with the usual capital, governance and controls requirements. Describing a firm as approved or regulator backed on the basis of sandbox participation is generally restricted by the test conditions.
Are sandbox firms exempt from anti-money laundering rules?
No. Regulators can waive or modify certain of their own rules where the legislation permits, but statutory obligations such as anti-money laundering, sanctions screening and data protection continue to apply in full during a test.
Should a new brokerage apply for a sandbox place?
Usually not. Brokerage is a well understood activity with a published authorisation route, so a supervised test answers a question the regulator does not have. An innovation hub conversation costs nothing and is the better first step if there is genuine uncertainty about which permission applies.
About the Author
Roman Onta is an Executive Director at SINGUARD. He builds the Prop Firm CRM, the Broker CRM, Scalegram and CopySignals side by side with his brother Alex Onta, and he helped on the design of eTrader, the division Alex built and leads. His ground is worldwide payment processing, AML compliance and the corporate structures brokers are built on, work the two of them carry together, shaped by executive roles in the UAE and international corporates. He lives and works in Dubai for most of the year. Meet the executive duo leading Singuard's five divisions.