Fintech founders lose sleep over compliance. So what keeps a compliance startup founder up at night? That is where I started the conversation with Aurimas Bakas, CEO and co-founder of Copla, on episode 50 of the Embedded Finance Review Podcast.
Aurimas is a serial fintech entrepreneur, and each company grew out of the last. He co-founded Paysolut, a core banking provider for licensed financial institutions across Europe, and sold it to SumUp in 2021. Selling to the financial industry as a critical vendor meant proving his own security and compliance to every customer, long before DORA existed. That is where the Copla idea came from.
From there, we get into how Copla helps both licensed financial institutions and their vendors manage DORA, ISO 27001, and other frameworks end to end, where AI genuinely helps with compliance and where a human still needs to decide, and his advice for founders facing DORA for the first time.
Key Takeaways:
- How each of Aurimas's ventures seeded the next, from a Lithuanian payment institution to core banking to compliance
- Why he saw DORA coming years before it existed, from his years selling core banking to licensed financial institutions
- How Copla works as a layer of registers for vendors, assets, risks, and incidents, with AI agents producing the reports, documentation, and training regulators ask for
- Where AI genuinely helps with compliance work, and where a human still needs to own the decision
- Why 2025 was the year of market education on DORA, and why 2026 is when audits actually start biting
- Why managing DORA and ISO 27001 on spreadsheets breaks as a fintech scales
- Why Copla focuses exclusively on the financial industry rather than being a generalist compliance platform
- His advice for founders facing DORA for the first time, and why proportionality means DORA for a twenty-person e-money institute is not DORA for a big bank