Wallet Funding, Float, and Stored-Value Operations
Wallets are accepted everywhere as a payment method. Here's the other side: how they're funded, who holds the float, and what safeguarding actually requires.
Accepting GrabPay, OVO, DANA, or M-Pesa is the easy part. This covers the liability side: funding rails, who holds the float and earns on it, why safeguarding, insurance, and trust are different protections, and what happens to balances nobody spends.
A wallet balance is a liability someone else holds for the customer, not free-floating value. Funding runs via card top-up, bank transfer, cash agent networks, or payroll credit, each with a different reversal profile. The float sits somewhere specific: Kenya requires trust-held funds, 100% liquid-asset backing, and daily reconciliation (Central Bank of Kenya); Indonesia treats it as customer-owned custodial funds, bankruptcy-remote from the issuer, split at least 30% into bank deposits and up to 70% into government securities (Bank Indonesia, PBI 23/6/2021); the UK tightens reconciliation and audit rules from 7 May 2026 without a statutory trust yet. Segregation, insurance, and trust are legally distinct protections. Negative balances happen despite prepaid design. Unspent balances split into accounting breakage and legal escheatment, which must never be treated as the same money.
Operators integrate GrabPay, OVO, and DANA, M-Pesa, and dozens of similar digital wallets as acceptance methods without much thought for what happens on the other side of that QR code or STK push. A wallet balance is not free-floating value. Every unit of it was funded from somewhere, is currently held by someone, and sits inside a regulatory regime that decides what happens if the wallet operator fails, a balance goes negative, or a customer never spends what they loaded. That is the liability side of wallet acceptance — funding rails, float economics, safeguarding law, and the two failure modes (negative balances, unclaimed balances) that acceptance-focused wallet coverage tends to skip.
This matters for a narrow but real set of operators: platforms building their own stored-value product, embedded-finance teams evaluating whether to hold float directly or route it through a partner, and anyone who has ever had to explain to a finance team why "the wallet balance" isn't sitting in the company's own bank account the way it looks like it should.
How Wallets Actually Get Funded
A wallet's opening balance always originates from one of a small number of funding rails, and each carries a different reconciliation and reversal profile.
Card top-up routes a card transaction into the wallet ledger. It's the most universally available funding method, but it inherits card-network dispute risk on the funding leg: a chargeback filed against the original top-up transaction — weeks after the wallet balance has already been spent — creates a shortfall the operator has to absorb, not the customer. This is a distinct risk from card acceptance chargebacks and is easy to under-provision for.
Bank transfer / account-to-account (A2A) top-up routes a real-time or batch bank transfer into the wallet. In Indonesia, this typically runs over BI-FAST, the central bank's instant interbank rail; in other markets it's PayNow, UPI, or a local equivalent. A2A top-up is usually irrevocable once settled — the funding-side mirror of the irrevocability question payout rail selection covers on the payout side. That irrevocability is good for the operator (no clawback risk once credited) but means a misdirected or duplicated top-up has no scheme-level undo button.
Cash agent networks fund wallets in markets with lower card and bank penetration. M-Pesa's Cash Merchant network is the reference model: a customer deposits cash with an agent, receives a one-time voucher to validate the transaction, and the agent's Log Book serves as the conclusive record of what happened at the point of sale. Reconciliation here depends on the agent's physical record matching the digital ledger — a different failure surface than a card or bank rail, and one that shows up later in this article's reconciliation section.
Payroll and salary top-up credits a wallet directly from an employer or platform — gig-economy earnings access being the clearest example. Merchant cashback and refund-to-wallet route money back into the balance from a prior transaction rather than a fresh funding event, which is where negative-balance risk usually starts (a refund issued against a balance that's already been spent elsewhere).
Float: Who Holds It, Where It Sits, and Who Earns On It
"Float" is the aggregate value sitting in customer wallet balances at any given moment — funded but not yet spent. It is the single most consequential number in a wallet business, because regulators size their scrutiny to it and the operator's own balance-sheet treatment of it determines who actually benefits from holding it.
Two regimes make the mechanics unusually visible.
Kenya requires an e-money issuer to maintain liquid assets equal to 100% of outstanding e-money, unencumbered and held separately from the issuer's other operations, reconciled daily by 4:00pm East Africa time against outstanding e-money — any shortfall must be fixed by noon the next day and reported to the Central Bank of Kenya. M-Pesa's own customer terms name the mechanism concretely: M-PESA Holding Company Limited is the Trustee, operating under a Trust Deed dating to 2007 (amended in 2008 and 2020), holding customer cash in trust. Customers are told plainly that no interest is paid on their balance — and the regulation leaves interest earned on the underlying liquid assets to the issuer's own discretion. The float sits in trust, but the yield on it is the operator's to keep.
Indonesia takes a related but distinct approach. Bank Indonesia's regulation defines dana float as the entire outstanding value of issued and topped-up e-money still owed to users and merchants — and states explicitly that this is not the issuing PJP's own asset. It is the e-money user's property held in the PJP's custody as dana titipan (custodial funds), and if the PJP is declared insolvent, that float is carved out of the bankruptcy estate entirely. Placement is prescriptive: at least 30% in cash or demand deposits at a BUKU 4 (systemically significant) bank, up to 70% in Indonesian government securities or Bank Indonesia instruments, adjusted monthly against a trailing 12-month liquidity model that's monitored daily. The float must sit in an account separate from the PJP's own operational account and cannot be pledged as collateral for anything else.
Elsewhere, the picture is less visible from what could be independently verified for this article. In the UK and EU, e-money law requires either a segregation arrangement or an insurance/guarantee arrangement (more on the difference below), but neither the UK's nor the EU's published rules that could be confirmed here specify who is entitled to any investment income the safeguarded assets generate — that detail is left to the individual firm's own terms, so check the specific wallet's customer agreement rather than assuming a universal answer.
Safeguarding, Insurance, and Trust Are Not the Same Word
This is the distinction most wallet coverage conflates, and it matters because the three mechanisms fail differently.
Segregation means customer funds are ring-fenced in a designated account, separate from the operator's own operating capital. It stops the operator from spending customer money on its own expenses, but it does not change ownership: the operator still legally holds the account, and the protection only works if segregation was actually maintained day-to-day — which is precisely why regulators increasingly demand frequent reconciliation rather than trusting a firm's initial account structure.
Insurance/guarantee substitutes a third party's promise: a bank or insurer guarantees repayment to customers if the operator fails. This is a claims-based backstop, not a change in who owns the money before failure — and it is only as good as the policy's actual terms. The UK's tightened rules, for instance, now require that such policies have no conditions or restrictions on paying out beyond certification of an insolvency event, precisely because looser guarantee terms had been a known weak point.
Trust is the strongest of the three: legal title stays with the operator, but beneficial ownership sits with the customer from the moment funds are received, which is what actually pulls the money outside the operator's bankruptcy estate. Indonesia's dana titipan model and Kenya's Trust Deed structure both function this way in substance, even though only Kenya uses the word "trust" directly. The UK, by contrast, does not currently impose a statutory trust: the FCA's finalized reforms — new mandatory daily reconciliations, annual independent audits for firms safeguarding over £100,000, monthly regulatory reporting, and formal resolution packs to speed up fund recovery — take effect 7 May 2026, but a statutory trust was proposed and explicitly deferred rather than adopted, over concerns about the knock-on effects of imposing one. A trust-based end-state remains possible later, contingent on further consultation and HM Treasury action; operators tracking the EU's own accelerated safeguarding timeline under PSD3/PSR will recognize the pattern — segregation and audit requirements tightening well ahead of the broader legislative package.
The EU's underlying e-money law permits either segregation or an insurance/guarantee arrangement, in the same shape as the UK's regime, though the precise timing rules in the directive's original text could not be confirmed here — EUR-Lex's hosted copy returned empty on every attempt, a known access issue, so this article relies on industry restatements rather than the primary legal text for that jurisdiction.
The US has no single federal answer: money transmission is licensed state by state, and coverage of "stored value" specifically is still expanding — Massachusetts's amended money transmission law only extended licensing to stored value from 1 October 2025, an activity its prior law didn't reach at all. At least seven states have adopted the Money Transmission Modernization Act in full, with roughly ten more revising existing statutes toward it, but the resulting protections (permissible-investments requirements, any trust-like characterization of those investments) vary enough by state that a specific figure could not be responsibly generalized here — check the statute in the state where the program is licensed rather than assume a single US-wide rule.
Negative Balances and Overdraft Risk in a Stored-Value Wallet
Wallets are prepaid by design — spend what's loaded, nothing more — which makes negative balances feel like they shouldn't exist. They happen anyway, and PayPal's own published mechanics are the clearest public description of why: a negative balance arises from a failed bank-funded payment, a dispute opened without enough balance to cover it, a chargeback, a refund issued for a buyer complaint, a payment recovery not covered by seller protection, or unauthorized account access. None of these are top-up failures — they're downstream consequences of transactions that already happened against money that, in hindsight, wasn't really there.
The recovery mechanics are worth building into any wallet's own design, whether or not PayPal's specific numbers apply: incoming funds get applied to the negative balance first, before anything reaches the customer; a multi-currency wallet can offset a negative balance in one currency against a positive balance in another, and a negative balance sitting in a foreign currency for 21 days gets force-converted to the wallet's base currency; and an unresolved negative balance eventually escalates — account lock or limitation, then referral to a debt collector. A stored-value operator that hasn't designed for negative balances has usually just been lucky with volume so far, not immune to the problem structurally.
Breakage and Escheatment: What Happens to Money Nobody Spends
Unspent wallet balances split into two problems that get conflated constantly, and shouldn't be.
Breakage is an accounting question: under ASC 606, a company can recognize revenue on the portion of a stored-value balance it reasonably expects will never be redeemed, using a proportional method that recognizes breakage in step with actual redemption activity, supported by historical redemption data. A remote/full method — waiting until redemption is highly unlikely before recognizing anything — applies only when a company can't reasonably estimate breakage at all.
Escheatment is a legal question: unclaimed-property law that requires an operator to turn dormant balances over to a state or government after a defined period, rather than keep them. The critical rule connecting the two: balances subject to escheatment must be excluded from breakage revenue calculations, because that money is legally the state's claim, not the operator's revenue. Recognizing it as breakage and then having a state successfully claim it is a double failure, not a rounding error.
US treatment illustrates how jurisdiction-specific this gets. The federal CARD Act sets a floor — a gift card or stored-value instrument generally can't expire within five years of activation, and inactivity fees are restricted — but state escheatment rules vary sharply on top of that floor. New York treats 100% of an expired card's value as abandoned property; North Carolina treats only 60%; California doesn't generally allow most gift cards to expire at all; Wyoming and New Hampshire split treatment above and below a $100 threshold. This is not an exhaustive list, and it changes by state and by instrument type — an operator building a US stored-value product needs its own state-by-state legal review, not a rule of thumb borrowed from this article or any other.
Indonesia's regulation takes a structurally different position: a PJP may set an expiry on the e-money media — the card, chip, or app — but that expiry cannot erase or extinguish the unused e-money value underneath it, and the PJP is required to tell users about media expiry and offer a way to resolve the leftover balance. GoPay's own terms illustrate the distinction in practice: a GoPay account goes dormant after 360 days with no transaction, and Gojek can suspend, limit, or close a dormant account — but that governs access to the account, not forfeiture of the value inside it, which the underlying regulation protects regardless. A "dormant" wallet in Indonesia is not the same event as an "escheated" balance in the US.
Kenya's e-money regulation, at least in the text available for this article, doesn't set out an e-money-specific dormancy or escheatment regime at all — no such provision appeared in the Central Bank of Kenya's E-Money Regulations. That doesn't mean nothing applies; it means an operator holding Kenyan wallet balances should ask counsel which general unclaimed-asset framework, if any, reaches e-money specifically, rather than assume either the US or Indonesian model transfers over.
Top-Up Failure Modes and Reconciliation
The funding side has its own version of the reconciliation problem payout rail selection documents for payouts. Failed card top-up with debited funds happens when the card network captures the debit but the wallet ledger never gets credited — a callback timeout or dropped webhook, not a payment failure, and the money is genuinely gone from the customer's card without landing anywhere until someone reconciles it. Double top-up is the mirror problem: a retried request without an idempotency key credits the same top-up twice. Reversal handling needs the same idempotent design discipline already established on the disbursement side — a callback that arrives twice should never apply the same credit twice.
Agent-network reconciliation is its own category. M-Pesa's cash-agent flow generates a physical Log Book entry alongside the digital transaction, and the customer's one-time deposit or withdrawal voucher expires if not used within the prescribed window — meaning the reconciliation problem isn't just "did the API call succeed," it's "does the paper trail match the ledger," a genuinely different failure surface than a pure API integration.
What Regulators Actually Examine
Strip away the jurisdiction-specific language and the FCA, Bank Indonesia, and the Central Bank of Kenya are all circling the same four questions, just with different thresholds attached:
- Is segregation or placement actually maintained day-to-day, not just on paper? Kenya's answer is a hard daily cutoff (4:00pm EAT reconciliation, noon-next-day cure, mandatory next-day report to the regulator on any deficiency); Indonesia's is a rolling 12-month liquidity model monitored daily; the UK's incoming rules formalize "reconciliation days" and add annual independent audits once safeguarded funds cross £100,000.
- Does capital scale with float, or is it fixed regardless of how much the operator is holding? Indonesia is explicit here — ongoing capital requirements step up in tiers as float grows, plus a flat 5% risk-weighted surcharge on managed float for e-money-issuing PJPs.
- Is there a credible plan for what happens if the operator fails? The UK's new resolution-pack requirement exists specifically so a failed firm's safeguarded funds can be returned to customers quickly rather than tied up for months in an insolvency process.
- Is the float actually insolvency-remote, or merely segregated on a balance sheet the operator still controls? This is the real dividing line between Kenya's and Indonesia's trust/custodial models — where the float is carved out of the operator's estate by law — and a pure segregation regime, where ring-fencing depends on the operator having actually kept the ring intact.
An operator evaluating a new wallet market should ask these four questions of the local regulator's rulebook before asking about interchange or settlement speed — a fast, cheap wallet whose float isn't genuinely protected is a liability wearing a payment method's clothing.
Build vs Partner: Your Own Licence or a Licensed BaaS/Issuer Partner
Holding float directly means becoming the licensed entity yourself — the PJP in Indonesia, the e-money issuer in Kenya, the EMI in the UK or EU — with the full capital and compliance burden that follows, scaling with float as shown above. For most platforms that aren't already payments companies, that's a heavier commitment than the product justifies.
The alternative routes the obligation to a partner who already holds the licence. This is the embedded finance model: the operator distributes a wallet-like product under its own brand while a sponsor bank, EMI, or BaaS platform actually carries the safeguarding, trust, and capital obligations behind it. The tradeoff is control for speed — the operator gives up direct visibility into exactly how the float is placed and safeguarded, in exchange for not having to build and maintain a trust structure, a daily reconciliation process, and a capital buffer that scales with adoption.
Neither path is free of the questions this article has walked through — building means owning them directly, and partnering means confirming, in writing, that the partner is actually answering them. A partner's marketing page saying "your funds are safe" is not a substitute for knowing whether that safety is segregation, insurance, or trust, and what the regulator in that specific market actually requires of it.
Sources & methodology (10)
Dana float (all outstanding e-money value from issuance and top-ups) is not an asset of the PJP administering it — it is the e-money user's asset held in the PJP's custody as dana titipan (custodial/bailment funds), and is expressly excluded from the bankruptcy estate if the PJP is declared insolvent. E-money value held by the PJP is not a "simpanan" (deposit) under banking law. Placement: at least 30% in cash or demand deposits at a BUKU 4 (systemically significant) bank, and up to 70% in government securities/liquid instruments issued by the Republic of Indonesia or Bank Indonesia, or in a Bank Indonesia account — adjusted to the issuer's trailing 12-month average monthly liquidity need, monitored daily. Float must be recorded in a segregated account apart from the PJP's operational account and cannot be used as collateral or for any purpose other than meeting obligations to e-money users and merchants. Separately, ongoing capital for a Category 1 PJP administering e-money is risk-weighted transaction exposure plus a 5% surcharge on managed float. A PJP may set an expiry on the e-money media (card/chip/app) but that expiry cannot erase or extinguish unused e-money value, and the PJP must inform users of media expiry and provide a mechanism to resolve the unused balance. Closed-loop e-money issuers with float under IDR 1 billion are exempt from PJP licensing.
Original Indonesian regulatory text; figures and provisions translated for this article. Fetched and parsed locally with pdftotext after the hosted PDF returned as unparseable binary through the standard web-fetch tool.
Checked:
E-money issuers must maintain liquid assets equal to 100% of outstanding e-money issued, unencumbered, and held separately from balances relating to any other operations of the issuer. Issuers must, by no later than 4:00pm East Africa time daily, reconcile liquid assets held for redemption against outstanding e-money; any deficiency must be rectified by 12:00pm the next day and reported to the Central Bank of Kenya by 4:00pm the day after discovery, describing the cause and remedy. The Bank may require an issuer to hold liquid assets across more than one bank. Interest earned by the issuer on liquid assets may be applied at the issuer's discretion. An e-money issuer's board must reflect that the company holds funds in trust on behalf of e-money holders as a condition of authorization.
Fetched and parsed locally with pdftotext after the hosted PDF returned as unparseable binary through the standard web-fetch tool. No dormant-balance or escheatment provision was found in this text — Kenya's e-money-specific dormancy treatment is not confirmed here.
Checked:
M-PESA's Trustee is M-PESA Holding Company Limited. A Trust Deed (dated 23 January 2007, amended 19 June 2008 and 20 July 2020) constitutes the trust under which the Trustee holds all cash received for a customer's Account in trust for that customer. A customer's Account balance is redeemable at any time via the M-PESA System. No interest is paid on funds held in an M-PESA Account. Cash Merchant transactions are recorded in a Log Book that serves as conclusive evidence of a completed transaction; deposit and withdrawal vouchers at ATM/vending outlets expire if not used within the prescribed timeframe.
Checked:
A GoPay account becomes dormant after no transaction for 360 consecutive calendar days; Gojek may then suspend, limit, or permanently close the dormant account if there is no outstanding obligation between the user and Gojek. GoPay electronic money account balances are explicitly stated not to be a savings deposit under Indonesian banking law, are not covered by Indonesia's deposit insurer (Lembaga Penjamin Simpanan), and carry none of the features typically attached to a bank account.
Checked:
Current UK safeguarding law (Electronic Money Regulations 2011, Payment Services Regulations 2017) allows firms to protect customer funds via a segregation method (ring-fenced designated accounts or low-risk liquid assets, not commingled with operating capital) or an insurance/guarantee method (a third-party bank or insurer guarantees repayment on the firm's failure). The FCA's finalized reforms (an interim state ahead of a possible later end-state) introduce mandatory daily reconciliations, annual independent audits for firms safeguarding over £100,000, monthly regulatory reporting, formal resolution packs to speed fund recovery in insolvency, and tightened insurance/guarantee provider terms (e.g., no exclusions beyond certified insolvency, minimum cancellation-notice periods). The FCA considered but did not implement a statutory trust over safeguarded funds in this phase, citing concerns about the impact of imposing one; a trust-based end-state (legal title with the firm, beneficial ownership with the customer) remains a possible later step contingent on further consultation and HM Treasury action. The interim rules take effect 7 May 2026.
The FCA's own safeguarding pages (fca.org.uk) returned HTTP 403 to both the standard fetch tool and a browser-user-agent curl request, so this article cites law-firm restatements of the published policy rather than the regulator's text directly.
Checked:
The EU's E-Money Directive (2009/110/EC) permits electronic money institutions to safeguard customer funds using either a segregation method (placing funds in dedicated safeguarding accounts with authorized banks, or investing them in low-risk liquid assets, ring-fenced from the EMI's own operating capital) or an insurance/guarantee method (a third-party bank or insurer guarantees repayment if the EMI fails), used instead of or alongside segregation.
EUR-Lex's hosted text of Directive 2009/110/EC (both the HTML viewer and the consolidated PDF) returned empty content on every fetch attempt, consistent with a known access issue — this article relies on an industry restatement rather than the primary legal text, and omits specific timing figures (e.g., a business-day count) that could not be independently confirmed from a document actually fetched in this session.
Checked:
At least seven US states (Arizona, Indiana, Iowa, Minnesota, North Dakota, Tennessee, and Texas) have enacted the Money Transmission Modernization Act in full, replacing their prior money transmitter statutes, with at least ten more states (including Georgia and Nevada) revising existing statutes in line with it. Massachusetts's amended money transmission law, effective 1 October 2025, extends licensing to the sale or issuance of stored value — an activity the state's prior law did not cover.
US money transmission licensing is state-by-state; this article does not assert a specific permissible-investments percentage or trust characterization because the state-supervisor and statute pages that would confirm those details (CSBS, North Carolina, Colorado) returned HTTP 403 on every fetch attempt.
Checked:
Under ASC 606, breakage revenue (the portion of a stored-value balance a company reasonably expects will never be redeemed) is recognized proportionally, in step with actual redemption activity, when the amount is reasonably expected and can be estimated from historical redemption data; a remote/full method — recognizing breakage only once redemption becomes highly unlikely — applies only when a company cannot reasonably expect any breakage. Balances subject to state unclaimed-property (escheatment) law must be excluded from breakage revenue calculations, because that money is legally destined for the state, not the business.
Checked:
The federal CARD Act sets a floor requiring most gift cards/stored-value certificates to remain valid for at least five years from activation and restricts inactivity fees, but state escheatment (unclaimed property) law varies substantially on top of that floor: New York treats 100% of an expired gift card's value as abandoned property; North Carolina treats only 60% as abandoned; California does not generally allow most gift cards to expire at all; Wyoming and New Hampshire apply a $100 threshold that splits how a card's value is treated above and below that line.
US unclaimed-property treatment of stored value is jurisdiction-specific beyond these examples. NCSL's state-by-state exemption map (documents.ncsl.org) was fetched but rendered as an unlabeled state grid that could not be reliably split into 'exempt' vs 'not exempt' columns from the extracted text, so it is not cited for specific state classifications.
Checked:
A PayPal balance goes negative from failed bank-funded payments, disputes opened without sufficient balance, chargebacks, refunds issued for buyer complaints, recovered payments not covered by Seller Protection, or unauthorized account access. While negative, incoming payments are applied first to clear the negative balance. In multi-currency accounts, PayPal may offset a negative balance in one currency against a positive balance in another; a negative balance held in a given currency for 21 days is automatically converted to US dollars. An unresolved negative balance can lead to account lock or limitation at 120 days, and PayPal may refer the debt to a collection agency.
Checked:
Source types explained in our Methodology.