UK fintech investment fell to £1.8 billion in the first half of 2026, down from £5.0 billion in the same period of 2025 and its lowest level since 2016, according to KPMG’s Pulse of Fintech H1’26 report. Even with that cautious picture, two of KPMG’s predictions for the rest of the year point in the same direction: infrastructure is becoming a major investment priority, and the growing focus on sovereign capability is moving into financial services.
For technology leaders at UK fintech organisations and financial institutions these trends are not separate. The decision to modernise core infrastructure is increasingly also a decision about where that infrastructure sits, who controls it, and the jurisdiction it ultimately answers to.

What the market is signalling
KPMG expects investor interest in infrastructure to extend well beyond stablecoins and digital assets, as traditional financial institutions work on their core infrastructure to compete more effectively and to better protect their data and core operations. It also notes that capital is concentrating on scaled, proven, infrastructure-focused businesses rather than early-stage experiments.
At the same time, KPMG predicts that the focus on sovereign capability, already visible in areas like AI and defence, will extend into financial services, with growing interest in regional solutions for digital identity, cybersecurity and wider financial services infrastructure. Across EMEA, it observes governments working to reduce reliance on capital and capabilities from outside the region, with the EU’s €5 billion Scaleup Europe Fund being one example.
For UK firms, the combined message is clear. The infrastructure you build will be judged on resilience and control, not just capability.
Sovereignty is more than data residency
Sovereignty is often reduced to a single question: is the data stored in the UK? Residency matters, but it is only one layer. It is more useful to think about four:
- Data residency: where data is physically stored and processed, including backups, logs, replicas and disaster recovery copies.
- Jurisdictional control: which legal regimes can compel access to that data. A provider headquartered outside the UK may be subject to foreign law regardless of where its servers sit; US-headquartered providers, for example, can be subject to the US CLOUD Act.
- Operational control: who administers the platform, from where, under what vetting and access controls, and whether you can evidence that for audit. It also means knowing who you call when something goes seriously wrong, and what they are contractually accountable for.
- Dependency and exit: how concentrated your critical services are on a single provider, and whether you could realistically move them if you needed to.
A firm can tick the residency box and still have limited control over the other three.
Why modernisation is the moment to decide
The core infrastructure modernisation KPMG describes is where sovereignty is won or lost. Retrofitting it later can be expensive: re-platforming workloads, re-architecting data flows and renegotiating contracts all take up both time and budget. Designing it in during a modernisation exercise mostly means making those deliberate choices early, while the architecture is still on the drawing board.
It matters to investors and acquirers too. With consolidation continuing across payments and the wider fintech market, and capital favouring already scaled businesses, infrastructure is increasingly examined during the due diligence process. Being able to show where critical data lives, who is able to access it, and how any of the services would continue if a supplier failed is part of demonstrating resilience and that a business is built to last.
It is also the point at which many firms discover their current provider is not scaling with them. Modernisation is a natural moment to ask whether the platform, the support model and the contractual accountability behind it are right for the next stage of growth.
Making the case to the board
For a CTO or technical director, sovereignty is ultimately a question of who carries the risk. When a critical service fails or a regulator asks for evidence, accountability sits with the company and not its suppliers, and it often lands with the person who signed off on the infrastructure.
That makes the case easier to put to a board than it might first appear. Sovereign-minded infrastructure is not a premium feature. It is a risk reduction measure with evidence attached: documented data flows, tested recovery, clear contractual accountability and an audit trail that stands up to ISO27001 and regulatory scrutiny.
With UK fintech investment at its lowest level in a decade and investors increasingly selective, infrastructure that is predictable in cost and does not lock the business into a single provider’s roadmap carries a value of its own. Pairing it with a FinOps discipline, so that spend is visible and forecastable, turns an infrastructure line item into conversations about resilience and control.
The regulatory backdrop
Regulators in the UK have not so much mandated sovereignty, but the direction is consistent. The FCA and PRA operational resilience framework requires firms to identify their important business services, set impact tolerances, and show that they can remain within them through severe but plausible disruption, and that includes disruption originating at third parties. The critical third parties regime reflects regulators’ concerns about the concentration of financial services on a very small number of technology providers. For firms serving EU customers, DORA adds its own expectations around ICT third-party risk and exit strategies. UK GDPR’s rules on international transfers add another reason to know exactly where any personal data flows, and that includes through support access and backups.
None of these requires infrastructure to be UK-only. What they do require is that you understand your dependencies, can evidence control over them, and have a credible plan if any one fails. The evidence that demonstrates this for resilience purposes is largely the same evidence ISO 27001 auditors and customers’ due diligence teams ask for, so an architecture designed with sovereignty in mind can pay back several times over.
Questions to ask of your infrastructure
- For each important business service, where does its data reside, including backups, logs and disaster recovery copies?
- Which legal jurisdictions could compel access to that data, directly or through your providers’ parent companies?
- Who has administrative access to the platform, where are they based, and can you evidence it for audit?
- Does your contract set out who is accountable, what the SLA covers, and who you call when something goes seriously wrong?
- How concentrated are your critical services on one provider, and what would it take to move them?
- Has your exit or failover plan actually been tested, or does it exist only on paper?
- Are sovereignty and resilience requirements written into your modernisation roadmap, or will they be addressed afterwards?
A pragmatic approach
Sovereignty does not mean abandoning hyperscale cloud. Most regulated firms will run a mix of platforms, and that is the sensible appraoch. The aim is intentional placement rather than accidental dependency:
- Classify workloads by criticality and data sensitivity, starting with your important business services.
- Place regulated data and critical services where jurisdiction, access and operational control are clear and can be evidenced.
- Use global platforms where their scale genuinely adds value and the associated risk is understood and accepted.
- Build for portability through infrastructure as code, open standards and documented data flows, so that exit is realistic rather than theoretical.
- Place routine operations with an accountable managed service where it makes sense, so your team spends its time on delivery rather than just keeping the lights on.
This is where the choice of partner matters. As a UK-based, ISO 27001 certified managed infrastructure provider, Pipe Ten operates across Azure, AWS and on-premise environments, so placement decisions are driven by your risk profile rather than by a single platform. For many firms the starting point is a Pipe Ten SAFER review, giving a clear view of where data and critical services sit today, where the dependencies are, and what needs to change. From there, we support clients with managed infrastructure, tested disaster recovery and business continuity, and fractional CTO or CISO support where strategic ownership is needed.
Key takeaways
- KPMG expects infrastructure to become a major investment priority, with financial institutions focusing on core infrastructure to compete and to protect data and operations.
- Sovereign capability is extending into financial services, driven by a wider push to reduce reliance on capabilities from outside the region.
- Sovereignty covers data residency, jurisdictional control, operational control, and dependency and exit, not residency alone.
- Accountability matters as much as location: know who is contractually responsible and who you call when something goes seriously wrong.
- Core infrastructure modernisation is the most cost-effective point to design sovereignty in, and it gives the board a risk reduction case backed by evidence.
- UK operational resilience expectations do not require UK-only infrastructure, but they do require understood, evidenced and recoverable dependencies.
Source: KPMG, Pulse of Fintech H1’26: UK perspective. Figures are based on PitchBook data as at 30 June 2026.
Author: Gavin Kimpton
A founder and CEO/CFO of Pipe Ten, Gavin has been a leader in the digital sector for over 30 years, specialising in web application hosting, domain registration, and international site launches. He has navigated evolving internet governance, from new top-level domains to security and compliance. Under his leadership, Pipe Ten became a Nominet-accredited channel partner, reflecting his deep expertise in the digital ecosystem.

Author: