B2B platforms have a US$185B embedded finance opportunity in front of them, and less than 20% of it is captured (Apideck, The State of B2B Embedded Finance 2026, June 2026). In Latin America the gap is regulatory: the product surface can be embedded, while holding funds, opening local accounts, converting currency and settling into a domestic rail each require a regulated entity per country.
In Latin America, a platform can embed the entire experience of a financial product: the account its customers see, the payment request, the conversion screen, the reconciliation report. What it cannot embed is the regulated act underneath. Holding client funds, opening a local account, executing a foreign exchange conversion and settling into a domestic clearing system are activities a regulator authorizes, and the authorization belongs to an entity, never to a piece of software. The dividing line sits between the product surface, which is software, and the flow of funds, which is licensed.
What can a platform embed without a license?
The product surface, in full. A platform can own the interface, the business logic, the balances its customers see, the trigger for a payment or a conversion, and the reporting around all of it, without becoming a regulated financial institution in Brazil, Mexico or Colombia. What it needs is a regulated entity underneath that performs the acts the platform is triggering.
In practice, that covers:
- the account experience end users see, backed by local accounts opened under a regulated entity;
- collecting payments through local methods and paying out in local currency;
- the currency conversion step, including the rate the customer sees before committing;
- holding stablecoin balances and ramping between local currency and stablecoins;
- the KYC and KYB flow, inherited from the regulated entity's own program instead of rebuilt;
- reconciliation, statements and audit trails.
A definition for anyone reading this section on its own: embedded finance is a non-financial platform offering financial products inside its own product, using another entity's regulatory permissions and rails. The platform owns the customer relationship. The entity owns the permission.
What actually requires a regulated entity?
Four acts, in every market we operate: holding client funds, opening a local account in someone's name, executing a foreign exchange conversion, and settling into a domestic clearing system. Each is a regulated activity, supervised by the local authority, and each one is where the answer to "who is responsible" has to have a name and a registration number.
This is also where "no local entity required" gets misread. The platform does not need to found a company in each country. The regulation does not disappear because of that. It stays in force, applied by whoever holds the authorization. ATTRUS operates that layer: local accounts, pay-in and payout, FX, stablecoin balances and inherited KYC and KYB, under our regulated infrastructure, so the platform ships the feature while we operate the licensed layer underneath.
Brazil authorizes the entity; Mexico and Colombia sponsor it
Brazil is the most explicit of the three. ATTRUS Instituição de Pagamento S/A is a payment institution authorized by the Central Bank of Brazil (BCB), under SISBACEN code 00141, and Brazilian foreign exchange runs under that authorization with an exchange contract issued per transaction. Pix accounted for 46.1% of Brazilian financial transactions in 2024 (Central Bank of Brazil), which is why a platform that cannot reach Pix cannot really sell into the market.
Mexico and Colombia are built differently. Both operate under locally compliant sponsor-institution frameworks, backed by registered local entities, with AML, KYC and foreign exchange controls aligned to local regulation. For the platform, the integration is the same across the three markets. Underneath it, the regulatory shape is not: one is an authorization held directly, two are frameworks operated with locally registered entities. Any provider that describes all three the same way is describing marketing, not structure.
US$185B, under 20% captured
Apideck sizes the B2B embedded finance opportunity at US$185B, with less than 20% of it captured (The State of B2B Embedded Finance 2026, June 2026). More than 80% is still on the table, and in Latin America the reason sits upstream of engineering. The feature is usually ready. The regulated layer under it is what takes months, because it is a question of entities, registrations and controls per country, not of endpoints.
That is the practical cost of reading the line wrong. A roadmap that treats "launch in Mexico" as an integration task ships late by the length of a regulatory process, and the delay does not show up in any engineering estimate.
54% of US B2B platforms report a revenue lift
Demand for this is measured, not assumed: 54% of US B2B platforms report a direct revenue lift from embedded finance (PYMNTS Intelligence/Marqeta, December 2025). The platforms capturing it are the ones that stopped treating the licensed layer as something to acquire and started treating it as something to connect to.
On our side of that connection, the scale is the argument: US$8B+ processed, 400+ clients, one integration. A platform enabling Brazil, Mexico or Colombia through it is making a product decision again, on a timeline it controls.
What does this change for a product roadmap?
It replaces build-or-buy with a more useful question: which regulated acts does this feature touch, and who holds the permission for each one? Three checks are enough to scope it.
- Does it hold, open, convert or settle? Those four verbs are the whole regulated set: client funds held, a local account opened in someone's name, currency converted, a domestic settlement executed. A feature that does none of them is pure software and ships on your own timeline.
- In which countries, and under which entity? Ask for the entity name, the registration and the regulator, per country. A single answer covering three countries is not an answer.
- What stays with you? Local consumer protection and securities regulation remain with the platform, along with billing and the product itself. The financial-rail compliance is what moves to the regulated entity.
The line between the two sides of that list is where the roadmap either compresses or slips. It is worth drawing before the sprint is planned, not after the launch date is announced.
Does a platform need a local entity to offer accounts in Brazil?
No. The accounts are opened under a regulated entity's authorization, so the platform does not need to found a company in Brazil. The regulation still applies in full, and it is applied by the entity holding the authorization. In our case that entity is ATTRUS Instituição de Pagamento S/A, a payment institution authorized by the Central Bank of Brazil (BCB) under SISBACEN code 00141.
Can a platform embed foreign exchange?
The platform can embed the whole experience, including the rate shown before the customer commits and the trigger for the conversion. The conversion itself is a regulated act. In Brazil it runs under our Central Bank of Brazil (BCB) authorization, with an exchange contract issued per transaction, which is what makes each conversion auditable after the fact.
Which entity and which regulator stand behind ATTRUS in each country?
In Brazil it is ATTRUS Instituição de Pagamento S/A, a payment institution authorized by the Central Bank of Brazil (BCB) under SISBACEN code 00141, and that is where ATTRUS holds its own authorization. Mexico and Colombia operate under locally compliant sponsor-institution frameworks, backed by registered local entities, with AML, KYC and foreign exchange controls aligned to local regulation. The two structures are not the same thing, and the difference matters when you are choosing who touches your customers' money in each country.
Can a platform embed card issuing or yield on balances?
Not through ATTRUS at this time. The embeddable scope today is local accounts for end users, pay-in and payout, foreign exchange, stablecoin balances with local currency ramps, and inherited KYC and KYB flows. Card issuing and yield on balances are not part of it, and a roadmap that assumes them should confirm with the provider before it is committed.
What is the difference between embedded finance and a payments integration?
A payments integration moves money for the platform. Embedded finance lets the platform offer financial products to its own customers, in its own product, under someone else's regulatory permissions. The second one changes what the platform sells, which is why it touches the licensed layer and a checkout integration usually does not.
This article states the rules as of August 2026, for Brazil, Mexico and Colombia.