FinTech Regulatory Sandboxes: A Country-by-Country Guide
GuideRegulation

FinTech Regulatory Sandboxes: A Country-by-Country Guide

27.08.2026

"Is there a sandbox?" is one of the first questions founders ask us about a new market. It is a reasonable question with an unreasonably complicated answer, because the word sandbox has been stretched to cover regimes that have almost nothing in common. In one market it means a genuine statutory exemption from three dozen financial laws. In another it means a regulator will watch you closely while holding you to every rule that already applies. Both are called sandboxes. Only one of them changes what you are allowed to do.

First, a distinction: two different things called "sandbox"

Before going further, it is worth separating two ideas that increasingly share a name.

A regulatory sandbox is about permission — a supervised arrangement in which a regulator lets you test a financial product on real customers under conditions it sets, sometimes relaxing rules that would otherwise apply. That is the subject of this guide.

A data sandbox is about information. It is a controlled environment, typically overseen by a central bank or financial regulator, in which financial institutions can pool or share data in a legally compliant way — most commonly to train and validate anti-money-laundering models, which individual institutions cannot do well alone because no single bank sees enough of the picture. Data sandboxes are a genuinely important development and a fast-growing area of supervisory practice, but they solve a different problem and deserve their own treatment. We will cover them in a separate post.

What follows is about regulatory sandboxes, across the 15 markets we work in. It is a general overview rather than legal advice — regimes change, and several details below carry a date for exactly that reason.

What a regulatory sandbox actually is

A regulatory sandbox lets a firm test a financial product on real customers under conditions the regulator sets: a capped number of users, a defined period, agreed reporting, and usually a narrow description of exactly what may be offered. That much is common to every regime here.

What differs — and it is the difference that matters — is whether the regulator also relaxes any rule while you test. This is the question to ask about any sandbox, and it splits the 15 markets into three groups.

The three kinds of sandbox

1. Genuine legal relief

The regulator suspends or waives specific requirements for the duration of the test. This is what most founders picture, and it is rarer than the marketing suggests.

South Korea is the clearest example anywhere in our coverage. Under the Special Act on Support for Financial Innovation, in force since April 2019, designation as an "Innovative Financial Service" by the Financial Services Commission (FSC) confers exemptions from roughly 34 enumerated financial statutes — covering authorisation, registration, reporting and business-scope rules. That is an actual statutory waiver, not a supervisory courtesy. Cumulative designations reached 1,075 as of 1 July 2026. A June 2026 reform went further, granting exclusive operating rights from the moment of designation rather than only after graduation.

Singapore also grants real relief, across three tracks run by the Monetary Authority of Singapore (MAS): the bespoke FinTech Regulatory Sandbox, negotiated case by case; Sandbox Express, a standardised track for well-understood lower-risk activities such as insurance broking and remittance, which can get a firm testing in around 21 days; and Sandbox Plus, which pairs Express with a grant for first-time applicants. If you are entering Singapore for the first time, Sandbox Plus is usually the relevant one, and it is the tier most guides omit.

Rwanda deserves more attention than it gets. The National Bank of Rwanda has run a sandbox since 2017, and Regulation N° 41/2022 gives it explicit power to temporarily relax specific regulatory requirements on a case-by-case basis. That is a firmer legal footing than several far better-known regimes. Testing runs 12 months, extendable once. Five things are never waived: AML/CFT, consumer protection, data privacy, cybersecurity, and fit-and-proper standards.

2. A restricted licence

Here you are genuinely licensed and supervised, but on a reduced scope — fewer permitted activities, capped volumes, lighter capital. You are not exempt from the law; you are authorised to do a smaller thing.

Most Gulf and Central Asian regimes work this way. ADGM's RegLab, regulated by the Financial Services Regulatory Authority, issues a bespoke authorisation with agreed activities and modified rules for up to about two years. The Dubai Financial Services Authority's Innovation Testing Licence is a restricted financial services licence appearing on the public register, for a 12-month test period, accepted on a rolling basis year-round; since 2017 the DFSA reports over 200 applications and more than 80 acceptances. Qatar's Qatar Central Bank runs a Regulatory Sandbox issuing a limited licence with capped customer numbers and transaction volumes, alongside a faster Express Sandbox added in 2024 for firms already licensed in another jurisdiction or partnered with a QCB-licensed entity. Kazakhstan's AIFC FinTech Lab, run by the Astana Financial Services Authority, issues a modified licence with reduced capital and compliance requirements; its public register currently lists 25 participants.

Kenya's Capital Markets Authority sandbox sits at the softer end of this group — it rests on a 2019 Policy Guidance Note rather than a binding regulation, runs up to 12 months, and is limited to capital-markets products. It is unusually open to foreign firms: you may apply as a Kenya-incorporated company or as a foreign company licensed by a securities regulator at home, provided you commit to launching in Kenya afterwards. Note that the Central Bank of Kenya does not run a sandbox — payments and digital lending go through ordinary authorisation — and that the Virtual Asset Service Providers Act 2025, in force since November 2025, splits virtual-asset licensing between the CBK and the CMA without creating a sandbox of its own.

3. Supervised testing with no relief at all

You are watched closely. Nothing is waived. This is a real category, and mistaking it for the first one is an expensive planning error.

China is the starkest case. There is no Western-style sandbox. The People's Bank of China operates a Fintech Innovation Regulatory Tool, piloted in Beijing from December 2019 and since extended city by city to Shanghai, Shenzhen, Chongqing and others. Its own governing logic treats existing law as a rigid baseline and uses public disclosure as the only flexible element — no participant is exempted from anything. It is also administered locally rather than nationally, and effectively gated through existing domestic licences, so participation generally runs through a licensed domestic entity.

Austria's FMA sandbox is statutory — § 23a of the Finanzmarktaufsichtsbehördengesetz, open to applications since September 2020, capped at two years, with an advisory board including the Ministry of Finance and the central bank. But the FMA is explicit that no provision may be suspended and that this is not a "licence light." You still need whatever licence the activity requires. Its value is structured access to the supervisor, not relief. Reported participation has been modest — eight firms, one of which had obtained a licence, as of the last figure we could confirm.

Vietnam is a newer entry and narrower than most people expect. Decree 94/2025/ND-CP took effect on 1 July 2025, administered by the State Bank of Vietnam, and covers exactly three activities: credit scoring, open API data sharing, and peer-to-peer lending. Participants receive a certificate limited to the named solution, and the decree states plainly that participation does not guarantee you will later satisfy licensing conditions. Applicants must be Vietnamese-licensed credit institutions or fintech companies established in Vietnam, and foreign-invested companies are barred from the P2P track.

A second, separate Vietnamese sandbox is on the way. The Vietnam International Financial Centre (VIFC) — established under Resolution 222/2025/QH15 and Decree 323/2025/ND-CP, spanning hubs in Ho Chi Minh City and Da Nang — is set to host its own fintech sandbox, with scope for temporary exemptions from certain legal and technical requirements. The operational detail is still being worked out, so it is not yet something to plan a market entry around, but it is worth watching: it would be considerably broader than the three activities Decree 94 covers, and it is aimed squarely at international firms rather than domestically established ones. Core obligations — data protection, cybersecurity, AML and foreign exchange rules — are expected to remain fully in force regardless.

Where there is no sandbox — and why that may not be the problem it sounds like

Four of our markets have no sandbox worth planning around. Before treating that as a gap, it is worth knowing that the most substantial academic work on the question argues the absence may be a feature.

In Building FinTech Ecosystems: Regulatory Sandboxes, Innovation Hubs and Beyond, Buckley, Arner, Veidt and Zetzsche compared sandboxes against innovation hubs — the less glamorous alternative, in which a regulator simply runs a proper channel for firms to ask how the rules apply to them. Their finding was blunt: innovation hubs deliver most of the benefits attributed to sandboxes while avoiding the costs, and the available data does not support the claim that sandboxes are the more effective way to build a fintech ecosystem. Their headline illustration is the UK, the market that started the trend: the FCA's sandbox had taken in 117 firms across five cohorts against more than 60,000 licensed UK financial institutions, while its innovation hub fielded over 500 support requests in eighteen months. Of the sandboxed firms in the first four cohorts, roughly 27% were no longer operating by the time they looked.

Read against that, the four markets below look less like laggards.

Germany has no financial regulatory sandbox, and this is a matter of principle rather than backlog. BaFin runs a FinTech Innovation Hub — a contact point offering guidance on how existing rules apply — but grants no exemption, holding that it has no legal authority to disapply financial regulation and that a sandbox would conflict with equal supervisory treatment: same business, same risk, same rules. Germany was already noted as a deliberate abstainer in the 2020 study above, alongside Luxembourg and most US regulators.

That said, Germany pursues the idea vigorously outside financial services. The Federal Ministry for Economic Affairs maintains a dedicated Reallabore (regulatory sandboxes) programme, built on experimentation clauses written into sectoral legislation that permit temporary derogation from a rule where it would otherwise block meaningful testing, supported by a Regulatory Sandboxes Innovation Portal and a cross-sector network. A federal Reallabore-Gesetz passed on 25 June 2026 to give this a general legal framework. Whether it operationally reaches BaFin-supervised financial services is genuinely unresolved — BaFin and the finance ministry raised the same equal-treatment objection during the legislative process. Treat it as a live question rather than a new route in, and watch it: if that objection is overcome, Germany's position could change materially.

The Netherlands is the clearest illustration of why the terminology is a mess. The 2020 study lists a Dutch sandbox dating from January 2017 and describes it as one that "leverages the scope offered by the law when interpreting the rules" — generous interpretation, but the rules still apply. Today DNB and the AFM describe the same arrangement in plainer terms: their joint InnovationHub, which has handled 650+ queries since 2016, is explicitly not a regulatory sandbox in which laws are temporarily set aside. Same mechanism, more honest label.

Israel has no standing sandbox. The Israel Securities Authority has run a FinTech Innovation Hub since 2018 as an advisory channel; a 2020 "Data Sandbox" with five firms was a one-off pilot; and proposed multi-regulator sandbox legislation has been discussed for years without confirmed enactment. The 2020 study reached the same conclusion, listing Israel among jurisdictions where a sandbox had been announced in the press but could not be verified against official sources. Six years on, that is still the position — and foreign fintechs enter through ordinary licensing regardless, as Revolut, Rapyd, Mesh Payments and Airwallex all did in 2025.

Hong Kong needs a caveat rather than a flat no. The HKMA's Fintech Supervisory Sandbox is substantial — 398 pilot trials permitted as of end-June 2026, 281 of them involving bank–tech firm collaboration. But it is open to HKMA-authorised institutions, meaning banks. An unlicensed startup does not enter it directly; it participates as a bank's partner, or uses the Fintech Supervisory Chatroom for early feedback. Separately, in March 2026 the HKMA, SFC, Insurance Authority and MPFA jointly launched a GenA.I. Sandbox++ with Cyberport, spanning banking, securities, asset and wealth management, insurance, MPF and stored value facilities.

India, and the EU layer above everything

India's Reserve Bank of India Regulatory Sandbox changed shape recently in a way that outdated guides still get wrong. It ran as five themed cohorts from 2019, but since April 2025 it operates on a continuous "on-tap" basis through the PRAVAAH portal — there is no cohort window to wait for. Direct applicants must be a bank licensed in India or a company registered in India; foreign firms without an Indian entity should look instead at the Inter-Operable Regulatory Sandbox, designed for products spanning multiple regulators.

For anyone entering Europe, three EU-level mechanisms matter more than any national sandbox:

  • The DLT Pilot Regime (Regulation (EU) 2022/858, in force since March 2023) is the closest thing to an EU-wide sandbox — genuine temporary exemptions from certain MiFID and CSDR requirements for market infrastructure using distributed ledger technology.
  • MiCA's transitional arrangements are frequently miscalled a sandbox. They are grandfathering: a wind-down window for firms operating under prior national regimes, without passporting rights, and member states chose different lengths.
  • The EU AI Act's sandboxes have been delayed. Article 57 required every member state to have an AI regulatory sandbox operational by 2 August 2026. The Digital Omnibus on AI moved that deadline to 2 August 2027 — reportedly because only one member state had one running. If your product depends on an EU AI sandbox, that timeline has shifted by a year.

What has changed since the last serious count

It is worth measuring today's picture against a fixed baseline. The 2020 Buckley study verified sandboxes in more than fifty jurisdictions against primary legal sources — the most rigorous count of its kind — and comparing it with our own markets shows how much has moved in six years, and how much has not.

  • Four of our markets have gained a regime since. Austria (September 2020), Vietnam (July 2025), Qatar and Rwanda's current legal basis (Regulation N° 41/2022) all post-date or fall outside that count. Vietnam's is the newest arrival in our coverage.
  • Two of the negatives have held for six years. The study could not verify sandboxes in China or Israel against official sources in 2020, and put them aside for that reason. Neither has one today. When a jurisdiction has been "about to launch a sandbox" for six years, that is information.
  • Germany's abstention was already deliberate then. It was named as a major financial system that had refrained, and it still has.
  • Kenya was listed as proposed, under the Capital Markets Authority. It launched, and the CMA remains the operator — a useful corrective, since the sandbox is often wrongly attributed to the Central Bank of Kenya.
  • Kazakhstan's AIFC regime was already there, dating to January 2018 and unusual even then for pairing the sandbox with a fintech office rather than running it alone.
  • Scale has changed more than coverage. Korea's regime was brand new in that count, recorded simply as starting April 2019. It has since issued over a thousand designations. The map has not expanded as dramatically as the busiest regimes have deepened.

When a sandbox is the wrong answer

Sandboxes are marketed as an on-ramp. Often they are a detour. Be honest about which you are looking at:

  • Your model is already clearly licensable. If an existing licence covers what you do, applying for it is usually faster than testing first and then applying anyway. Sandboxes exist for genuine novelty, not for ordinary businesses that would prefer a gentler entry.
  • The sandbox grants no relief. If you will be held to every rule regardless, the sandbox buys supervisory access, not speed. That can be worth a lot — or nothing — depending on how uncertain your regulatory treatment actually is.
  • An innovation hub may serve you better. If what you actually need is a straight answer about how you will be regulated, the hub is the faster and cheaper route, and in several markets it is the only one on offer. That is the central finding of the research above, and it matches what we see in practice.
  • You need a local entity anyway. Korea, India, Vietnam and, in substance, Rwanda all require a local vehicle to apply. If you were hoping the sandbox would let you test before committing to incorporation, it generally will not.
  • The scope is narrower than your product. Vietnam's covers three activities. Kenya's covers capital markets. A sandbox that does not cover what you actually do is not a route in.

Two common misconceptions

A free-zone licence is not onshore permission. This is the single most common misunderstanding we encounter, and it concerns the UAE. An ADGM RegLab authorisation or a DIFC Innovation Testing Licence lets you operate in that financial free zone. Neither automatically permits business with customers onshore in the UAE, which is regulated by the Central Bank of the UAE and the Securities and Commodities Authority. Dubai's 2025 reform allowing some free-zone companies to serve the mainland explicitly excludes DIFC. The CBUAE operates its own sandbox regime and a co-sandboxing arrangement designed to bridge onshore and free-zone testing — which exists precisely because that bridge is otherwise missing. Plan for two authorisations, not one.

A promotion agency is not a regulator. In Rwanda, the Kigali International Financial Centre and Rwanda Finance Limited market and facilitate the ecosystem; they do not license or supervise anyone. KIFC membership is genuinely valuable — it unlocks a 3% preferential corporate income tax rate against the standard 15%, plus 0% withholding and capital gains tax, subject to real economic substance in Rwanda. But it is a tax status, not a financial licence. Entering Rwanda properly means three separate tracks: company registration with the Rwanda Development Board, KIFC membership through Rwanda Finance, and BNR sandbox admission or licensing. Founders routinely collapse these into one and are surprised later.

What happens after the sandbox

Every regime here ends the same way: the sandbox is a bridge to a full authorisation, not a destination. Firms exit by applying for the licence proper, and regulators generally expect that trajectory from the outset — Kenya requires a commitment to launch locally after exit; the CBUAE expects intent to scale into the wider UAE market; ADGM firms must move to a full FSRA licence or leave.

Which means the useful question is not "can I get into the sandbox?" but "what does the licence I will eventually need require, and does testing first make that easier or merely later?" For a genuinely novel product in an unclear regulatory category, the sandbox earns its place: you get a supervisor's view of how you will be treated before you have spent a year building for the wrong answer. For a product that maps onto an existing licence, it usually does not.

Further reading

See how we support FinTech market entry — including regulatory strategy and licensing pathways across these markets
Ask us about a specific market — we'll tell you honestly whether a sandbox helps in your case
Asia · Europe · Africa — explore the FinTech ecosystem in each country we cover

This guide is general information, not legal advice, and reflects the position as of August 2026. Sandbox regimes change frequently — confirm current requirements with the relevant regulator, or ask us, before making a market entry decision.

All Posts