Lumon Pay Ltd

United Kingdom · www.lumonpay.com · 6 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 6 sub-vendors.

Insights

Last updated 2026-08-15 · revision 1

6 direct vendors, 146 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Lumon Pay Ltd exhibits a medium level of migration readiness, primarily due to a mixed technology landscape and significant data gaps. The presence of "Open Banking API Integration" and "API Integrations for Partner Connectivity" suggests a degree of modularity and an API-first approach for certain functionalities, which are beneficial for migration to modern cloud-native architectures. The "Custom Identity & Onboarding Platform" could also represent a modern, independently deployable component. However, several factors pose challenges. The core "Foreign Exchange (FX) Trading Platforms" and "Electronic Money Institution (EMI) Infrastructure" are not explicitly described as cloud-native, containerized, or microservices-based, indicating a potential reliance on more traditional or monolithic architectures that would require significant refactoring for a cloud migration. The company's website relies on "WordPress," which is not inherently cloud-native. Crucially, there is no information regarding the "Regulatory Environment" or "Data Residency Requirements," which are fundamental considerations that can significantly impact the scope, complexity, and cost of any migration effort. Financial stability, including the ability to fund a substantial migration project, cannot be assessed due to missing data on revenue concentration and growth history. The "Vendor Lock-in Risk" is explicitly "Unknown," and while vendor HQs are geographically diverse (US, AU), the exact number of unique vendors and the complexity of their contracts are not provided, making it difficult to assess potential vendor-related migration hurdles.

Compliance

14 in-scope frameworks identified; showing 3.

DORA (source) — Assessment Required

DORA (Regulation (EU) 2022/2554) became applicable on 17 January 2025 and directly applies to electronic money institutions, payment institutions, and investment firms operating in the EU. Lumon FX Europe Limited (CBI-regulated EMI in Ireland) is explicitly within DORA's scope as an EMI. DORA imposes comprehensive ICT risk management, incident reporting, digital operational resilience testing, and third-party ICT risk management requirements. Risk is High because: (1) DORA is directly applicable to Lumon's EU entity with no transposition required; (2) the January 2025 application date means Lumon should already be compliant; (3) DORA requirements are extensive and require significant investment in ICT governance, testing (including TLPT for significant entities), and third-party management; (4) Lumon relies on third-party ICT providers (Visa/CurrencyCloud for US payments, banking partners for safeguarding) which must be managed under DORA's ICT third-party risk framework; (5) non-compliance can result in supervisory measures and fines; (6) no public DORA compliance programme or assessment has been disclosed. The CBI is the competent authority for DORA oversight of Lumon FX Europe Limited.

Evidence: https://www.lumonpay.com/legal-info/, https://www.lumonpay.com/how-we-protect-your-money/, https://www.lumonpay.com/about-us/

Cyber Essentials Plus — Compliant

Lumon explicitly confirms Cyber Essentials Plus certification on its About Us page. Cyber Essentials Plus is a UK government-backed cybersecurity certification scheme that requires independent technical verification of cybersecurity controls. Achieving Cyber Essentials Plus (the higher tier) demonstrates that Lumon has implemented and independently verified baseline cybersecurity controls including: boundary firewalls and internet gateways, secure configuration, access control, malware protection, and patch management. Risk is Low as the certification is confirmed and current.

Evidence: https://www.lumonpay.com/about-us/

SOC 2 (source) — Assessment Required

Lumon Pay operates digital financial services platforms (online account management, trading platform, onboarding portal) and processes sensitive customer financial data. SOC 2 is highly relevant for fintech/payment companies as it provides assurance over security, availability, processing integrity, confidentiality, and privacy of customer data. While SOC 2 is not a legal requirement, it is increasingly expected by enterprise business clients, institutional partners, and counterparties in the financial services sector. Lumon serves both retail and corporate clients and has a partner programme, making SOC 2 attestation commercially important. Risk is Medium because: (1) absence of SOC 2 report may limit enterprise client acquisition and partner relationships; (2) the company processes high-value financial transactions (£7.2bn in 2025) requiring strong controls assurance; (3) no public SOC 2 report has been found. Risk is not High because Lumon holds Cyber Essentials Plus certification and is subject to FCA/CBI regulatory oversight which imposes overlapping security and operational controls requirements.

Evidence: https://www.lumonpay.com/about-us/, https://www.lumonpay.com/how-we-protect-your-money/, https://www.lumonpay.com/legal-info/

Financials

Financial Resilience Score: 6/10

Lumon Pay Ltd operates as an FCA-regulated Electronic Money Institution with a long operating history since 2000 and over 70,000 customers served. The company benefits from dual regulatory authorization in both the UK (FCA) and EU (Central Bank of Ireland via its Irish subsidiary), providing a post-Brexit passporting solution. Private equity backing from Pollen Street Capital since 2019 provides balance-sheet support and M&A capacity, and client-money safeguarding requirements ring-fence customer funds from company assets. However, the company operates in a highly competitive market against well-funded competitors like Wise, Revolut Business, OFX, Currencies Direct, Moneycorp, Argentex, and Ebury, creating persistent margin pressure. Revenue is sensitive to FX transaction volumes, particularly tied to UK-to-Europe property purchases which are vulnerable to Brexit effects, mortgage rate changes, and GBP weakness. The concentration in the property-abroad niche adds sectoral risk, and ongoing regulatory capital requirements may necessitate future equity injections. Without access to specific financial figures from Companies House filings, a definitive resilience score is difficult to determine. The score of 6 reflects the balance between strong regulatory positioning and PE backing versus competitive pressures and niche concentration.

Key strengths: FCA-authorized Electronic Money Institution (FRN: 902022), Dual UK/EU regulatory footprint with Irish subsidiary providing post-Brexit passporting, Long operating history since 2000 with 70,000+ customers served, Private equity backing from Pollen Street Capital since 2019, Client-money safeguarding required by FCA rules, Diversified customer base across retail and corporate B2B FX

Risk factors: Highly competitive market with Wise, Revolut, OFX, Currencies Direct, Moneycorp, Argentex, Ebury causing margin compression, FX-volume sensitivity tied to UK-to-Europe property purchases, Regulatory capital requirements for EMI/API status may require equity injections, Interest-rate exposure on safeguarded client balances, Technology/fintech competition from neobanks and API-first challengers, Concentration in the property-abroad niche (Spain, France, Portugal, Cyprus, Greece, Italy, Turkey, Australia, NZ, USA, Ireland)

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report