Field notes
Payments ·

Core banking vs BaaS: what you actually buy

Core banking is the system of record for money: the ledger that holds every account, every balance, and every posting, plus the rules that move value between them correctly. Banking-as-a-Service (BaaS) is renting someone else's core — and the regulated permission behind it — through an API instead of running your own. Between owning a core and riding an agent registration there is a spectrum, and where you sit on it decides what you build, what you rent, and what you are on the hook for. “Core banking vs BaaS” is not really a product comparison; it is a question about how much of the stack you want to own.

It is worth clearing up because the two get shopped for as if they were the same aisle. They are not. One is software that has to be correct; the other is a commercial arrangement that hands you correctness-as-a-service and bills you for it. Knowing which you are buying — and which you actually need — is most of the decision.

What “core banking” actually names

A core banking system is the ledger of record and the machinery around it. It holds the chart of accounts, maintains balances, records every posting in double entry so debits and credits always tie out, places and releases holds, accrues interest and fees, and produces the statements everything downstream reads from. It is the part of a bank that must be right, because if the ledger is wrong nothing built on top of it can be trusted. Everything else — the app, the card art, the notifications — is presentation. The core is the truth.

That is the first distinction to hold onto: the core is not the app. A customer sees an app; behind it, some ledger is keeping score. You can own that ledger, rent it, or ride on someone who owns one. Those three choices are the spectrum.

The spectrum: own core, BaaS, agent

At the heavy end you own the core outright: your ledger, your permission to hold or move money, your direct connections to the payment rails. In the middle sits BaaS: a licensed provider owns the core and the permission, and you build against their API — their accounts, their IBANs, their cards, wearing your brand. At the light end is the agent model: you hold no core and no licence of your own, operating instead under a licensed entity that has registered you. Each step down sheds capability and, with it, a slice of cost and obligation.

Owning your core: control, and the bill for it

Owning the core buys control. You set the product roadmap instead of waiting on a provider's. You hold accounts directly, connect to rails directly, and your unit economics stop being someone else's markup — at scale, the per-account and per-transaction rent you would have paid a BaaS provider becomes margin you keep. Nothing sits between your decisions and the ledger they land on.

The bill is large and mostly not software. You need the regulated permission (a separate purchase from the software, and often the harder one — the vocabulary of safeguarding, interchange, and settlement is collected at /glossary), the capital that permission requires, the compliance and operations headcount to run it, and direct integrations with each rail and scheme you touch. And correctness is now yours: when the ledger is wrong at 2am, there is no provider to call. You own the truth, which means you own the failures too.

BaaS: rent the core and the permission

BaaS collapses that bill into a monthly relationship. A licensed partner holds the accounts, issues the IBANs and cards, safeguards the float, and answers to the regulator; you build your app against their API and ship. What you buy is speed — a working, permissioned core on day one instead of a licence application and a ledger project. For most teams launching a first product, that trade is the right one.

What you give up is ownership. The provider's economics become your cost floor: you pay per account and per transaction, and those fees do not fall as you grow the way owned infrastructure does. The provider's limits become your limits, their roadmap gates yours, and you do not own the ledger — which makes leaving expensive and migration a project in its own right. BaaS is renting the correct part of a bank. Rent is cheap to start and never stops.

A core you own is a capital project that pays back at scale. A core you rent is an operating cost that never falls. The question is not which is better — it is which one your volume and margin have earned yet.
— Protocore · Payments engineering

The agent model: lightest of all

Lighter still, the agent model asks you to build almost nothing on the money side. You register as the agent of a payment institution or the distributor of an e-money issuer; their licence covers your activity, their core keeps the ledger, and the regulator knows you through them. It is the fastest way to put a branded financial product in front of customers and the one that leaves you with the least control — you are a face on someone else's rails, and their terms are your ceiling.

Where a whitelabel platform on your own core fits

There is a fourth position the spectrum hides: owning your core but not building the app layer from scratch. The regulated permission and the software that instructs it are separate purchases — you can hold your own licence and still buy the customer app, the operator console, and the theming as a platform on top. That is where a whitelabel platform sits. Protocore Pay (/products/pay) is the software layer on its own: a branded app platform and operator console that runs on whatever core and rails you bring — owned or partnered — without welding a licence to the sale. The console it comes with, where every privileged action requires a reason and lands in an audit log, is Protocore Center (/products/center).

Framing it this way is clarifying because it lets you price the two lines independently. The permission is judged on jurisdiction, safeguarding, and terms; the software is judged on whether the onboarding works, the ledger integration is clean, and operators can actually run the thing. Buying software does not commit you to a licence, and buying a licence does not hand you an app — a fact that quietly costs projects months when the two get confused.

Choosing your rung

The honest heuristic runs on volume, margin, and control. Launching, unsure of demand, moving fast: BaaS or an agent registration gets you live without a capital raise, and you accept the per-transaction rent as the price of speed. Growing, with volume high enough that the rent exceeds what your own compliance and infrastructure would cost, and with a roadmap a provider keeps blocking: that is when owning the core starts to pay back. Most products start rented and graduate to owned exactly once — when the numbers say the capital and the headcount are cheaper than the rent.

None of this is legal advice, and the category names shift by jurisdiction; treat it as the map you bring to a conversation with a regulator or an adviser, not a substitute for one. But the shape holds everywhere: core banking is the ledger you must have be correct, BaaS is renting that correctness by the month, and a whitelabel platform is the software you put on top of whichever you chose. Buy the rung your volume has earned — and buy the software and the permission as the two separate things they always were.

Have a system to build?

Tell us the problem. We'll come back with an architecture and a plan.

Contact us