A revenue milestone that is really a licence question

A finance lead approving a corporate card programme is usually comparing fee tables. Interchange rebates, foreign exchange margins, integration with the accounting system, how quickly a card can be issued to a new hire. What almost never appears on that comparison is the legal form of the company holding the money, and this week gave a reason to add the line. On 29 July, Pliant said it had passed 100 million dollars in annual recurring revenue. The figure is the company's own and is not audited, so read it as a statement rather than a filing, but the surrounding numbers are specific: more than 300 employees, eight offices, cards issued in over 13 currencies across more than 32 countries, and more than 5,000 business customers alongside 35 partners in Europe and the United States. Chief executive Malte Rau framed it as a shift in how businesses think about commercial payments rather than as a revenue event.

Pliant was founded in Berlin in 2020 and sells commercial cards two ways: directly to companies in travel, e-commerce, insurance and fleet management, and as a white-label product that banks, fintechs and software platforms put their own name on. It has held an e-money institution licence and Visa principal membership since 2023. That licence is the part worth pausing on.

An e-money institution is authorised to issue electronic money and execute payments. It is not authorised to take deposits or to lend against them, which is the defining activity of a bank. The practical consequence is not that the arrangement is weaker, but that it is governed by a different rulebook with different guarantees, and the difference lands precisely on the balance your company leaves sitting on the platform between funding and settlement.

What safeguarding does, and what it leaves out

Under the EU e-money framework, funds received in exchange for electronic money are explicitly not deposits, and the European Banking Authority has confirmed that they fall outside deposit guarantee schemes. In their place comes safeguarding, set out in Article 7 of the E-Money Directive, which gives an institution three ways to protect customer money: hold it in a segregated account at a credit institution, ring-fenced from the institution's own creditors; invest it in secure, low-risk liquid assets such as government bonds or money market funds; or cover it with an insurance policy or comparable guarantee for the full amount.

Read the two regimes side by side and the trade is clear rather than alarming. A deposit guarantee scheme pays out up to 100,000 euros per depositor per bank, quickly, backed by the state, and stops dead at that ceiling. Safeguarding covers the whole balance with no upper limit, which is materially better for a company holding 400,000 euros of working capital in a payments account, and it does so without a public backstop, which is materially worse if the protection itself fails. Neither is a scandal. What is a problem is that most treasury policies were written for the first regime and describe the second nowhere, so nobody in the business has ever decided which one they wanted.

The American leg runs on somebody else's permission

The same structural choice repeats in the United States, and there it is sharper. Pliant did not enter the American market with its own charter. On 14 July it announced a partnership with Coastal Financial Corporation, the Everett, Washington bank holding company listed on Nasdaq as CCB, which acts as its sponsor bank through its CCBX banking-as-a-service segment. The arrangement supports agent-based issuing structures and it is what makes the American programme legal.

For a customer this is a dependency with an unusual shape. Your card provider is a vendor you can change, on notice, with a migration project. The sponsor bank underneath it is not: it holds the permission the programme runs on, you did not select it, you have no contract with it, and if that relationship changed the programme would need re-papering rather than a switch flipped. It is the same lesson that arrived with cloud regions and with payment processors, in a place most companies have not yet thought to look. Coastal reports its second-quarter results on 30 July, which is as close as an outside customer gets to visibility on the counterparty behind the card in their wallet.

Three questions, and where the answers belong

None of this argues against using a non-bank issuer. The commercial case is real and Pliant's numbers say the market agrees: cards in more than 32 countries and 13 currencies is genuinely hard for a single national bank to match, and the reason a Berlin company reached this scale in six years is that the incumbents were slow to build it. The argument is only that the structure should be a decision on record rather than a detail discovered during an incident.

So write down three answers this quarter. Which legal entity holds our balance, and in which country is it authorised. Which safeguarding method under Article 7 does it use, segregation, secure assets or insurance, and can it name the credit institution or insurer. And which bank stands behind the card programme in each market where we issue. Any provider worth using answers all three in a paragraph, and a provider that cannot has told you something more useful than the answer would have been.

Then set a threshold. Decide the maximum balance the company is willing to hold on any payments platform at a point in time, sweep above it, and make that number part of the same policy that already governs bank counterparty limits. It converts an unexamined exposure into a managed one, which is the entire job.