AfterWorc Blog · Payments teams

Building a payments team: the hiring guide for EMIs, PIs and PSPs

Victor Birjukov · 9 Oct 2026 · 9 min read

  • Build the team in three stages: the people the regulator assesses before the licence, the people who run payments after it, then more depth as volume grows.
  • The first hires are rarely engineers: the application must describe governance, internal controls and AML/CFT controls, and the people who own them.
  • EU rules allow small firms to combine some roles, but the decision has to be documented and outsourced work stays your responsibility.

If you are working out how to build a payments team, the order you hire in matters more than the headcount. This guide sets out a payments team structure for EMIs, PIs and PSPs at each stage, from pre-licence to scale, and what to check before each hire. It describes what the rules ask for. It is not legal advice, so confirm the details with your regulator and your advisers.

Why a payments team at a licensed firm looks different

Most guides on building a payments team are written for merchants and platforms. Stripe's guide groups the team into product, operations and go-to-market. Checkout.com's groups it into analytics, product and operations. Both are useful if you take payments. Neither is built around a licence.

An electronic money institution (EMI), payment institution (PI) or payment service provider (PSP) that holds its own licence answers to a supervisor. That changes the first hires. Under PSD2, an application for authorisation must describe the applicant's governance arrangements and internal control mechanisms, and, where AML/CFT duties apply, the controls set up to meet them (Article 5(1)(e) and (k)).

The EBA's guidelines on authorisation go further. Applicants provide a detailed organisational chart and an overall forecast of staff numbers for the next three years (Guideline 5). They also give evidence of the knowledge, skills, experience, reputation and integrity of directors and the people who manage the firm (Guideline 16).

So your first payments team is partly written into the application. The people you name have to exist, be suitable and be able to do the job.

Stage 1: Before the licence – who do you need first?

At this stage you are building the people and documents a supervisor will assess. In Estonia, for example, Finantsinspektsioon asks for information on managers, including each management board member's areas of responsibility, details of the internal auditor and a description of internal controls for anti-money laundering compliance.

The roles that usually come first:

  • Management board members with clear areas of responsibility. Supervisors assess their suitability, so pick people whose experience matches the services in your application.
  • An AML/CFT compliance officer. The EBA guidelines on AML/CFT compliance officers (EBA/GL/2022/05) expect a firm to name a management body member responsible for AML/CFT, and in most cases a separate compliance officer. Not appointing one has to be justified and documented.
  • A risk and compliance lead to write and own the policies the application describes: risk assessment, internal controls, business continuity and the security policy (EBA Guidelines 11 and 13).
  • A head of payment operations to design how payments will actually flow, including safeguarding of client funds where it applies (EBA Guideline 7).
  • An internal auditor. Finantsinspektsioon asks for the internal auditor's details in the application. Many small firms use an outsourced provider for this.

Engineering can start here too, especially if you are building your own platform. But the regulator reads the governance first.

Stage 2: Licence granted – who runs payments day to day?

Once you are authorised, the work shifts from writing policies to running them. This is where most of the team gets hired. We covered the core of it in the five roles your payments team needs before your first PSP goes live.

Typical hires at this stage:

  • Payments operations specialists to handle exceptions, returns, chargebacks and scheme or bank queries.
  • AML/KYC analysts to onboard customers and review alerts. Our guide to hiring an AML / KYC analyst for an EMI covers what to check before the interview.
  • A reconciliation or finance operations analyst to match what you expect against what banks and schemes report, and to support safeguarding checks.
  • Payment integration developers to connect banks, schemes and partners, and to keep those connections working.
  • An ICT risk or security lead. The Digital Operational Resilience Act (DORA) has applied to payment institutions and e-money institutions since 17 January 2025, with no transitional period. It covers ICT risk management, incident reporting and ICT third-party risk. Someone has to own that.

At this stage many roles are combined. One person may cover fraud and transaction monitoring. One engineer may own two integrations. That is normal while volumes are low, as long as the combination is recorded and the person has the time.

Stage 3: Scaling – when do you split roles?

As volume, products and countries grow, combined roles become a risk. Signs it is time to split:

  • Alert queues or onboarding backlogs grow week on week.
  • One person holds knowledge nobody else has, such as a bank integration or a reconciliation process.
  • You add a new product, scheme or country, and the risk assessment changes.
  • An audit or supervisory review finds that a control depends on one person.

Common splits at this stage: fraud separated from AML monitoring, a dedicated AML/CFT compliance officer if the role was combined, a payments product manager, and a data or payments analyst. Our article on how to hire a payments specialist goes through the individual roles in more detail.

Keep an eye on the rules too. In November 2025 the European Parliament and the Council reached provisional agreement on PSD3 and the Payment Services Regulation, and commentators expect them to apply from 2027. Check the final text and its dates before you plan headcount around it.

Payments team structure by stage

  • Before the licence – goal: get authorised. Hire: management board, AML/CFT compliance officer, risk and compliance lead, payments operations lead, internal audit (often outsourced). The regulator looks at governance, internal controls, AML/CFT controls, the suitability of managers, the org chart and the three-year staff forecast.
  • Licence granted – goal: run payments safely. Hire: payments operations, AML/KYC analysts, reconciliation, integration developers, an ICT risk or security lead. The regulator looks at whether controls work in practice, safeguarding where it applies, and DORA ICT risk management.
  • Scaling – goal: grow without single points of failure. Hire: separate fraud and AML monitoring, payments product, data and analytics, more depth in each team. The regulator looks at whether controls keep pace with new products, countries and volume.

Should you hire, outsource or combine roles?

EU rules allow some flexibility, within limits.

  • Combining roles. Under the EBA guidelines, the management body decides whether the AML/CFT compliance officer role is full time or combined with other functions, based on the firm's size, complexity and risk.
  • Outsourcing. Operational tasks of the AML/CFT compliance officer can be outsourced, but the firm keeps ultimate responsibility. The EBA authorisation guidelines also ask applicants to describe their outsourcing arrangements and provide draft outsourcing agreements.
  • Hiring. Roles the supervisor treats as key, such as management board members, usually need to be your own people with documented suitability.

A practical rule: if a role is named in your application or holds a regulatory responsibility, plan to hire it. If it is execution work with clear procedures, such as alert reviews in a busy month or a one-off integration, outside specialists can carry it while you hire.

How much does a payments team cost?

There is no honest single figure. Salaries depend on country, seniority and the role. What you can do is calculate it the same way every time.

For people you employ directly, the cost is gross salary plus employer taxes in the country of employment, plus recruitment and onboarding time.

If you hire through AfterWorc, the price is the specialist's salary plus employer taxes plus a 10% AfterWorc margin. For fixed-price tasks, such as a single integration or a policy review, the AfterWorc fee is 5–8% of the task price, and funds are held until you accept the work. We do not quote team totals in advance because they depend on who you choose.

What to check before each hire

  1. Does the role appear in your application or org chart? If yes, the person's background has to match what you told the regulator.
  2. Who owns each control? Every policy needs a named owner with time to run it.
  3. Is the role combined? If so, write down why, and when you will split it.
  4. Is any part outsourced? Check the contract covers what your supervisor expects. The responsibility stays with you.
  5. Can the candidate show real work? Ask about specific alerts handled, integrations shipped or reconciliations fixed, not just titles.
  6. What happens if this person leaves? If the answer is "nobody else knows how", plan a second person.

AfterWorc interviews every specialist by video and gives them a practical test before you see them.

FAQ

What is the first hire when building a payments team for an EMI or PI? Usually the people the regulator will assess: management board members and an AML/CFT compliance officer. The application must describe governance, internal controls and AML/CFT controls, so the people who own them come before most engineers.

Can one person be the compliance officer and the MLRO at a small EMI? The EBA guidelines let the management body decide whether the AML/CFT compliance officer role is full time or combined, based on size and risk. A decision not to appoint a separate officer must be justified and documented. Check your national rules and your supervisor's expectations.

Can we outsource AML work? Operational AML/CFT tasks can be outsourced, but the firm keeps ultimate responsibility for compliance. Your authorisation application should describe outsourcing arrangements and include draft agreements.

Does DORA apply to payment institutions and EMIs? Yes. DORA has applied to payment institutions and e-money institutions since 17 January 2025, with no transitional period. It covers ICT risk management, ICT incidents and ICT third-party risk.

How many people does a payments team need? There is no fixed number in the rules. The EBA authorisation guidelines ask for a three-year staff forecast, and the right size depends on your services, volume and risk. Start with the roles your application names, then add depth as volume grows.

Sources

Building a payments team? Tell us the roles and get three matching profiles for each. Start hiring on AfterWorc. The first 10 business clients get €190 off their first hire and a free technical assessment.