Back to Glossary

Regulatory Sandbox

Regulatory Sandbox Definition: A regulatory sandbox is a framework in which a financial regulator lets firms test new products or business models with real customers for a limited time under relaxed or tailored rules. Each test runs inside agreed limits, such as a cap on customer numbers or transaction size, and the regulator monitors it closely before deciding whether the product can launch at full scale.

What Is a Regulatory Sandbox?

Financial rules were written for banks, brokers and insurers that already exist. A startup with a new idea, such as a crypto payment app or an automated lending model, often cannot tell which rules apply to it, and getting a full licence can take a year or more. A regulatory sandbox solves that problem by giving the firm a controlled space to try the idea before the rulebook is settled.

The term borrows from software development, where a sandbox is an isolated environment in which code can run without damaging the main system. In finance, the isolation comes from limits instead of code: a small group of customers, a short testing window and constant contact with the regulator. The UK Financial Conduct Authority (FCA) opened the first widely copied sandbox in 2016, and the Monetary Authority of Singapore published its own framework the same year.

Sandboxes sit at the centre of how regulators handle fintech. They let a supervisor learn how a new product behaves before writing permanent rules for it, which is why so many early crypto and tokenisation experiments passed through one.

How Does a Regulatory Sandbox Work?

For a trader or investor, the useful question is what the sandbox actually changes for the firm inside it. The answer is a sequence of gates. First, the firm applies and must show that its product is new, that it benefits consumers and that it needs live testing to prove itself. The regulator then agrees a test plan covering the number of customers, the maximum exposure per customer, the length of the test and the data the firm must report.

During the test, the firm operates under a restricted authorisation or a no-action letter, and it still has to meet core compliance duties such as customer identification and clear disclosure. At the end, three outcomes are possible: the firm applies for a full licence, it changes the product, or it shuts the test down and follows its exit plan.

Consider a hypothetical startup that wants to let users pay merchants in stablecoins. Its sandbox plan might allow 500 customers, each limited to £1,000 of balances, for six months. If the startup’s custody provider fails in month four, the loss is capped at £500,000 across all users, and the exit plan already states how that money will be returned.

That cap is the point of the design. The regulator accepts a small, known risk in exchange for real evidence about how the product behaves with real users. If the six months pass without problems, the firm arrives at its full licence application with data instead of promises.

Types of Regulatory Sandboxes

Product sandboxes accept individual firms in cohorts, usually once or twice a year, and test one product per firm. The original FCA model works this way, and it remains the most common format.

Thematic sandboxes focus on one problem, such as financial inclusion or digital identity, and invite firms that address it. They help a regulator compare several solutions at the same time.

Industry-wide regimes change the rules for a whole category of activity rather than for one firm. The EU DLT Pilot Regime, which applies from March 2023, lets market infrastructures trade and settle tokenized securities on blockchains under temporary exemptions, and the UK opened a similar Digital Securities Sandbox in 2024.

Cross-border sandboxes let a firm test in several countries under coordinated supervision. The Global Financial Innovation Network, formed by regulators in 2019, ran pilot tests of this kind.

Regulatory Sandbox vs. Innovation Hub

Regulatory Sandbox Innovation Hub
What the firm gets Permission to test live with real customers Guidance on how existing rules apply
Real customers involved Yes, within agreed limits No
Rules relaxed Sometimes, for the test only Never
Time frame Fixed testing window, often 6 to 12 months Open-ended contact
Typical output Test results and a licence application Informal regulatory feedback

Many regulators run both. A firm usually starts with the innovation hub to learn whether it needs a licence at all, then moves into the sandbox if live testing is the only way to answer the remaining questions.

Why Is a Regulatory Sandbox Important for Traders?

Sandboxes shape which products reach the market and how fast. When a regulator sees a product working safely at small scale, it gains the evidence it needs to write proportionate rules, and that often decides whether a new asset class becomes tradable at all. The FCA’s own review in October 2017 found that about 90% of first-cohort firms that completed testing were continuing towards a wider launch, which shows how often a test turns into a real business.

The main risk is reading a sandbox badge as a stamp of approval. A firm in a sandbox has permission to experiment, not a full licence, and its customer limits exist precisely because the product might fail. Marketing that says a project is “regulated” when it is only in a sandbox deserves the same scepticism as any other unverified claim, and the firm’s status can be checked on the regulator’s public register.

Sandboxes also create a quieter problem: regulatory shopping. Firms can pick the country with the loosest testing terms, and a product approved in one sandbox may face very different treatment elsewhere. Anyone tracking crypto regulation should treat a sandbox result as evidence about one jurisdiction, not a global green light.

Key Takeaways

  • A regulatory sandbox lets firms test new financial products with real customers for a limited time under a regulator’s close supervision.
  • Each test runs within agreed limits on customers, exposure and duration, so any failure causes a small, known loss rather than broad harm.
  • Sandboxes come in several forms: firm-by-firm product cohorts, thematic programmes, industry-wide regimes and cross-border pilots.
  • Unlike an innovation hub, which only gives guidance, a sandbox allows live testing and can lead directly to a full licence application.
  • Sandbox status is not a full licence, and a product that works in one country’s sandbox may still face different rules elsewhere.
FAQ section

Does a regulatory sandbox mean a firm is licensed?

No. Most sandboxes grant a restricted, temporary permission tied to a specific test, and the firm still needs a full authorisation before it can serve the general public.

Are customers protected when they use a sandbox product?

Partly. Regulators usually require disclosure, customer caps and an exit or compensation plan, but the product is still an experiment and customers can lose money if it fails.

Which country launched the first regulatory sandbox?

The UK Financial Conduct Authority opened the first widely copied sandbox in 2016. Singapore, Hong Kong, Australia and many other jurisdictions followed within a few years.

Can a crypto project join a regulatory sandbox?

Yes, if the jurisdiction's sandbox covers the activity. Tokenised securities, crypto payments and custody services have all been tested in sandboxes, although each test is limited to what the regulator approves.

Security Token Offering (STO)
Security Token Offering (STO) Definition: A security token o...
Social Engineering Attack
Social Engineering Attack Definition: A social engineering a...
Travel Rule (Crypto)
Travel Rule (Crypto) Definition: The crypto Travel Rule is a...
Sybil Attack
Sybil Attack Definition: A Sybil attack is an attack in whic...

Live Chat

Contact our support team via live chat.

Help Center

Questions about our services?
Check out our Help Center.

Risk Warning:
Trading in leveraged products carries a high level of risk and may not be suitable for all investors.