Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What is the difference between a digital full…
Governance, Ownership & Risk

What is the difference between a digital full bank and a digital wholesale bank in practice?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 24, 2026 Domain: Governance, Ownership & Risk

A digital full bank is designed to serve retail customers and can take retail deposits, subject to staged capital and product limits during the initial phase. A digital wholesale bank serves non-retail segments such as SMEs and cannot take ordinary individual deposits, aside from limited fixed deposits. The distinction matters because it changes the customer base, funding model, and regulatory burden.

How the customer base changes the bank’s purpose

The practical difference starts with who each licence is meant to serve. A digital full bank is built for retail customers and therefore has to handle consumer-facing onboarding, deposits, disclosures, complaints, and everyday payment behaviour. A digital wholesale bank is aimed at non-retail segments such as SMEs, so the product design, account structure, and service model are narrower and more business-oriented.

That distinction is not just legal wording. It changes how the institution is marketed, what kinds of accounts it can offer, how much consumer protection posture it needs, and how the operating model is framed from day one. In practice, the bank’s permissions, controls, and customer journeys are all designed around that target population.

For a retail-focused bank, the operating model has to assume high account volumes, diverse customer behaviours, and stronger expectations around accessibility and dispute handling. For a wholesale bank, the emphasis is usually on relationship banking, business onboarding, and fewer, more structured customer types.

How funding and deposit-taking differ in practice

The clearest commercial difference is deposit-taking. A digital full bank can take retail deposits, but during the early stage it is often subject to staged capital and product limits. A digital wholesale bank cannot take ordinary individual deposits, although it may accept limited fixed deposits from permitted counterparties. That shapes liquidity planning, funding stability, and balance-sheet growth.

Because retail deposits can be a low-cost and sticky source of funding, a full bank model usually has a broader funding base over time. A wholesale bank is more constrained and typically relies on a narrower set of funding relationships, which makes product design and client selection more important. The restriction also affects how quickly the bank can scale deposits without breaching licence conditions.

This is where commercial flexibility meets supervisory constraint. The licence type determines whether the institution is building a consumer deposit franchise or a more limited business banking proposition. The difference affects pricing, treasury planning, capital management, and the speed at which the institution can broaden its offerings.

What the regulatory burden changes day to day

The regulatory burden differs because the risk profile differs. A digital full bank faces the obligations that come with retail banking, including stronger conduct expectations, customer protection requirements, and more intensive oversight of consumer-facing processes. A wholesale bank has a narrower customer base, but it still needs controls appropriate to business banking, including onboarding, transaction monitoring, and governance over permitted deposit products.

In practice, this means the full bank has a wider compliance surface. It must support retail-grade disclosures, complaints handling, product governance, and operational resilience across higher transaction volumes and more varied customer scenarios. A wholesale bank is less exposed to retail conduct risk, but it still has to show that its products and controls match the limits of its licence and the nature of its clients.

The practical takeaway is that these are not simply two versions of the same bank. The licence type shapes the institution’s customer promise, the source of its funding, and the amount of regulatory work required to keep the model within bounds.

Risk and Threat Considerations

The main risk is misalignment between licence, product design, and actual customer activity. If a bank on a wholesale model starts behaving like a retail deposit institution, or if limits are misunderstood, the result can be regulatory breach, funding pressure, or a forced redesign of the product set.

Failure mechanism: The bank expands outside its permitted customer or deposit profile, or operational controls fail to stop prohibited account types or deposit structures from being offered.

Impact: That can trigger supervisory action, capital or product restrictions, remediation work, and reputational damage, especially if customers were onboarded under assumptions the licence does not support.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-01 — Organizational ContextLicence type defines the bank's operating context and intended customer segment.
GV.RM-01 — Risk Management StrategyDifferent licence models create different compliance and funding risks.
Recommendation — Document the bank's permitted customer base and funding model as operating context. Align product and funding strategy to the risks of the chosen banking licence.
ISO/IEC 27001:2022A.5.31 — Legal, statutory, regulatory and contractual requirementsThe distinction is governed by licence-specific banking obligations.
A.5.36 — Compliance with policies, rules and standards for information securityOperations must stay within the rules attached to the banking model.
Recommendation — Map licence conditions to the controls and products the bank is allowed to offer. Verify that customer onboarding and deposit products comply with the approved banking model.

Practitioner Guidance

What to verify: Treat the licence as an operating constraint, not a branding choice. Verify that onboarding rules, account types, deposit products, and marketing language all match the permitted customer segment and funding permissions.

Decision rule: If the business model depends on broad, low-cost deposits from individuals, the full-bank pathway is the relevant one. If the institution is designed around business clients and limited deposit capture, wholesale licensing is the more coherent fit.

What good looks like: Product, treasury, compliance, and operations all work from the same customer and funding assumptions, so the bank does not need to retrofit controls after launch.

Practitioner takeaway: The practical distinction is not just who the bank can call a customer, but how far the institution can stretch its funding model and product ambition without running into licence limits.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 24, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org