P@SHA · Pakistan IT Industry Association Policy Portal

Thematic cluster

Digital Payments & Fintech

Wallets, Raast, e-money, lending, sandbox licensing · 8 documents in the library

Sector landscape

By Rahnuma · AI-generated

Pakistan's digital payments and fintech ecosystem has undergone rapid regulatory formalization from 2018-2023, establishing layered frameworks for instant payments (Raast), e-money institutions, digital banking, and digital lending while maintaining robust consumer protection timelines and AML/CFT obligations.

Pakistan has built a multi-tiered instant payment infrastructure through the Raast framework (2021), requiring 99.9% system uptime and establishing interoperable rails across participating PSPs. The 2023 EMI Regulations replaced the 2019 framework, raising the Capital Adequacy Ratio to 10% and introducing tiered penalty structures (PKR 500,000 minor, PKR 10 million major non-compliance) alongside enhanced AML/CFT obligations requiring 24-hour STR filing. The licensing architecture differentiates between EMI categories (PKR 500 million minimum capital for Category I, PKR 100 million for Category II) and separate pathways for digital banks, P2P lending platforms, and sandbox testing participants.

Consumer protection standards are quantified with specific deadlines: EFT regulations mandate 45-day complaint resolution, 30-day unauthorized transfer reporting windows, and 3-day failed transfer re-credit timelines. Multi-factor authentication is required for transactions above PKR 50,000. The 2023 EMI Regulations establish wallet limits of PKR 50,000 balance and PKR 200,000 monthly transactions for basic accounts, with KYC thresholds at PKR 25,000. Monthly reporting obligations apply across EMI operators (4 times yearly), digital banks (monthly financial, quarterly prudential), and sandbox participants.

Dual regulatory authorities (SBP and SECP) have established parallel sandbox frameworks: SECP's 2019 Non-Banking Financial sandbox and SBP's 2021 Digital Financial Services sandbox with 60-day application review periods and 6-month testing phases. The 2022 Digital Lending/NBFC Regulations amended two existing frameworks to accommodate P2P and BNPL business models, while the 2022 Digital Bank Licensing Framework introduced fit-and-proper requirements, technology risk assessment mandates, and prompt incident notification obligations.

Outlook — watch this over 12–24 months

Over the next 12-24 months, Pakistan's digital payments sector faces several inflection points requiring close monitoring. First, the rollout and adoption velocity of Raast will be critical—regulators and industry participants should track transaction volumes, PSP onboarding completion, and whether interchange fee caps are finalized, as these will determine merchant and bank participation incentives. Second, the conversion of existing EMI operators under the stricter 2023 Regulations will test regulatory capacity, with 90-day license application processing timelines and CAR requirements potentially consolidating the market. Third, digital bank licensing authorizations under the 2022 framework remain a key development to watch, as these will set precedents for technology-forward banking operations in Pakistan. Fourth, sandbox outcomes from both SBP and SECP cohorts will reveal whether these controlled environments are effectively bridging innovative fintechs to full licensure or creating regulatory bottlenecks. Finally, coordination between SBP and SECP on entities falling under dual jurisdiction (particularly digital lending platforms that may also issue e-money) will determine whether Pakistan develops a coherent fintech regulatory architecture or persists with fragmented oversight. Compliance cost escalation, particularly for smaller PSPs managing 24-hour STR filings, monthly reporting, and 3-day re-credit obligations, may create market consolidation pressure.

Top frictions in this cluster

Dual Regulator Jurisdiction Creates Compliance Complexity

SBP and SECP operate separate sandbox environments, licensing pathways, and supervisory regimes for overlapping fintech business models, forcing market entrants and existing operators to navigate bifurcated regulatory requirements with potential inconsistencies in capital, reporting, and consumer protection standards.

High Minimum Capital Thresholds Limit Market Entry

EMI Category I requires PKR 500 million minimum capital and Category II requires PKR 100 million, combined with 100% safeguarding requirements and 25% mandatory liquid assets, creating substantial barriers for startups and smaller fintechs seeking to formalize operations.

Compressed Consumer Protection Timelines Strain PSP Operations

The 3-day failed transfer re-credit obligation and 45-day dispute resolution requirement under EFT Regulations, combined with monthly sandbox reporting and 24-hour AML STR filing mandates, impose significant operational and compliance infrastructure demands on smaller payment service providers.

Raast Interoperability and Fee Structure Uncertainty

While Raast establishes the national instant payment rail with 99.9% uptime requirements, interchange fee caps remain subject to SBP fee regulation, creating business model uncertainty for PSPs and potentially limiting merchant adoption incentives until transparent pricing is finalized.

Frequent Regulatory Framework Updates Create Implementation Gaps

EMI regulations have evolved from 2019 to 2023, requiring operators to repeatedly upgrade compliance systems, reporting mechanisms, and capital structures, with potential transitional gaps during implementation of the 2023 framework's 90-day license application processing and 10% CAR requirements.

Incomplete Sandbox Parameters Create Uncertainty for Innovators

SECP's 2019 sandbox guidelines leave key parameters unspecified (testing duration, customer limits, transaction caps, application fees), while SBP's 2021 sandbox limits are also Not specified, creating planning uncertainty for fintechs evaluating controlled testing as a market entry pathway.

Key numbers in this cluster

Customer Complaint Resolution Period
45 days
Electronic Fund Transfers (EFT) Regulati...
Unauthorized Transfer Reporting Window for Full Protection
30 days
Electronic Fund Transfers (EFT) Regulati...
Failed Transfer Re-credit Timeline
3 business days
Electronic Fund Transfers (EFT) Regulati...
Maximum Administrative Penalty for Non-compliance
10 million PKR
Electronic Fund Transfers (EFT) Regulati...
Mandatory Multi-Factor Authentication Threshold
50,000 PKR
Electronic Fund Transfers (EFT) Regulati...
Maximum ATM Withdrawal Fee (Regulated Tariff)
0.5 percent
Electronic Fund Transfers (EFT) Regulati...
Pre-Transaction Fee Disclosure Requirement
0 seconds delay allowed
Electronic Fund Transfers (EFT) Regulati...
Maximum Dispute Resolution Escalation Days Before SBP Intervention
45 days
Electronic Fund Transfers (EFT) Regulati...
Original Effective Date
2019
Regulations for EMIs: Original (2019)
EMI License Categories
2 categories
Regulations for EMIs: Original (2019)
Minimum Capital - Category I
500 million PKR
Regulations for EMIs: Original (2019)
Minimum Capital - Category II
100 million PKR
Regulations for EMIs: Original (2019)
Safeguarding Requirement
100 percent
Regulations for EMIs: Original (2019)
Unlicensed Operation Fine
varies PKR
Regulations for EMIs: Original (2019)
License Renewal Period
3 years
Regulations for EMIs: Original (2019)
Single Transaction Limit (Category II)
25,000 PKR
Regulations for EMIs: Original (2019)
Reporting Frequency (Monthly)
12 reports/year
Regulations for EMIs: Original (2019) · annual
Liquid Asset Ratio
100 percent
Regulations for EMIs: Original (2019)
Guidelines Issuance
2019 year
SECP Regulatory Sandbox Guidelines
Maximum Testing Duration
not specified in available summary time period
SECP Regulatory Sandbox Guidelines
Customer Limit During Testing
not specified in available summary number
SECP Regulatory Sandbox Guidelines
Transaction Cap During Testing
not specified in available summary PKR amount
SECP Regulatory Sandbox Guidelines
Application Fee
not specified in available summary PKR
SECP Regulatory Sandbox Guidelines
Testing Phase Extensions Allowed
not specified in available summary extensions
SECP Regulatory Sandbox Guidelines
Post-Testing License Application Deadline
not specified in available summary days
SECP Regulatory Sandbox Guidelines
Capital Requirement During Testing
not specified in available summary PKR
SECP Regulatory Sandbox Guidelines
Sandbox Fee
not specified in available summary PKR
SECP Regulatory Sandbox Guidelines
Maximum Cohort Participants
not specified in available summary entities
SECP Regulatory Sandbox Guidelines
Testing Period Duration
not specified in available summary months
SECP Regulatory Sandbox Guidelines
Testing Period Duration
6 months
Guidelines for Regulatory Sandbox (Digit... · initial term, extendable
Minimum Customer Limit
Not specified customers
Guidelines for Regulatory Sandbox (Digit...
Applicant Capital Requirement
Not specified PKR
Guidelines for Regulatory Sandbox (Digit...
Application Review Period
60 days
Guidelines for Regulatory Sandbox (Digit... · from complete application
Unauthorized Testing Penalty
Not specified PKR
Guidelines for Regulatory Sandbox (Digit...
Maximum Customer Loss Exposure
Not specified PKR
Guidelines for Regulatory Sandbox (Digit...
Reporting Frequency
Monthly reports
Guidelines for Regulatory Sandbox (Digit... · during testing
Sandbox Cohorts Per Year
Multiple batches
Guidelines for Regulatory Sandbox (Digit... · annual
System Uptime Requirement
99.9 percent
Raast: Instant Payment System · annually
Full KYC Transaction Limit
varies by participant PKR
Raast: Instant Payment System · per transaction
Limited KYC Transaction Limit
varies by participant PKR
Raast: Instant Payment System · per transaction