Key Regulatory Challenges in P2P platforms
After the 2008 crisis, demand for alternatives to traditional banking gave rise to peer-to-peer lending. With that growth came a regulatory landscape that now sits at the centre of every product decision.
by Polina Nikolova · Feb 22, 2024
The Great Recession changed how people thought about financial services. Faced with tighter bank lending, slower transfers and rising fees, consumers and small businesses started looking for alternatives — cheaper cross-border payments, easier access to credit, and new ways to invest, including crypto assets such as Bitcoin, Ethereum and Litecoin.
Peer-to-peer (P2P) lending platforms were one of the most visible answers. Founded in the years just before the crisis, they grew rapidly afterwards as banks tightened their criteria and a large share of loan applications were rejected. That mismatch between demand for credit and supply from traditional lenders created the space for a new wave of operators.
As these platforms scaled, so did regulatory attention. The need for Anti-Money Laundering (AML) programmes and compliance specialists grew quickly, and the talent market followed. As one industry AML officer put it, fintechs went 'from a simple advantage due to a lack of regulation to a regulatory landscape that has expanded' — and now compete for the same compliance resources as the banks they once disrupted.
All financial institutions are expected to operate under rules covering money laundering, terrorist financing and the transfer of funds. P2P platforms are no exception. Customer due diligence, risk assessment and ongoing monitoring are not optional extras — they are core product responsibilities.
The regulatory landscape
The last decade has seen a steady increase in legislation aimed at preventing financial crime. For P2P platforms, this translates into several practical building blocks that need to be designed into the product, not bolted on later.
AML (Anti-Money Laundering). An AML programme defines how a company detects and reports suspicious activity. A dedicated officer typically owns the controls, monitoring accounts and assessing risk profiles. Suspicious patterns — large unexplained cash movements, inconsistent account information, links to high-risk jurisdictions — are reported to the relevant authorities. The Financial Action Task Force (FATF) provides the globally accepted baseline for these controls.
KYC (Know Your Customer). KYC is the broader identification process used by financial institutions to know who they are dealing with. For a P2P platform, it shapes onboarding, account verification, and the limits a user can operate under.
CDD and EDD. Customer Due Diligence (CDD) is the standard check on identity, background and risk category. Enhanced Due Diligence (EDD) is triggered when a customer falls into a higher-risk bucket — for example politically exposed persons (PEPs), nominee shareholders, or users connected to jurisdictions with weak AML systems, sanctions exposure or high corruption scores. EDD typically requires stronger evidence and more frequent review.
Internal controls. Beyond customer-facing checks, platforms need internal controls: due diligence on partners and counterparties, clear reporting lines for suspicious transactions, and continuous training so teams keep up with regulatory change.
MiFID, MiFID II and the FCA
Markets in Financial Instruments Directive (MiFID), introduced in 2007, raised transparency standards across the EU and pushed firms to strengthen their compliance functions. MiFID II, effective from January 2018, levelled the playing field with third-country firms operating in the EU, introduced stricter cost transparency, more rigorous transaction reporting, and pushed more over-the-counter activity onto official venues.
In the UK, the Financial Conduct Authority (FCA) brought P2P lending under formal supervision in 2019. The intent was clear: give users access to better information about how lending and borrowing actually work, and ensure platforms operate with the same discipline as other regulated firms.
Following its 2016 review of the sector, the FCA introduced changes that took effect on 9 December 2019. Key examples include a 10% cap on the share of a non-advised investor's portfolio that can sit in P2P lending, mandatory pricing of credit risk, and an appropriateness assessment of investor knowledge before an account is opened. Platforms also need minimum capital relative to the size of their loan book and a contingency plan describing how loans would be managed in the event of platform failure.
What this means for product teams
For product teams, the practical lesson is that regulation is not a final layer added at the end of the design process — it shapes the product itself. Identity verification, risk profiling, disclosures, limits, audit trails and wind-down plans all surface as UI, workflow and data decisions.
Treating compliance as a product capability — owned jointly by product, design, engineering and risk — leads to cleaner experiences, stronger relationships with banking partners and regulators, and platforms that can scale without rebuilding their foundations. The teams that internalise this early move much faster than those who treat it as paperwork.
References
The Economist (2015), 'From the People, For the People'. Adtalem Global Education (2017). NorthRow, 'Money Laundering and Compliance in the Peer-to-Peer Industry'. FATF, Recommendations. Investopedia: MiFID, MiFID II, Over-the-Counter Market. Transparency International, Corruption Perceptions Index. US Department of State, State Sponsors of Terrorism. Sum & Substance, AML Compliance and Enhanced Due Diligence guides. Lending Works, 'FCA regulation of the peer-to-peer lending industry'.
Key takeaways
- Compliance is a product capability, not a final layer of paperwork.
- AML, KYC, CDD and EDD each translate into concrete workflow and data decisions.
- MiFID II and FCA supervision changed what a P2P platform must expose to users.
- Designing controls early avoids rebuilding the foundations later.