
Founder & Managing Director, CamFinTech
William Mallett founded CamFinTech to do the regulatory approval-navigation and compliance work that getting onto Cambodia's Digital Public Infrastructure rails actually requires — the layer that's unowned by law firms, system integrators, and the rails' own DIY channels.
CamFinTech is a fee-only regulatory and compliance practice based in Phnom Penh. We prepare Cambodian and foreign institutions to meet the standard for connecting to Cambodia's national rails — Bakong/KHQR (payments, NBC), CamDX/CamDigiKey (identity and data exchange, TSC), CamInvoice (e-invoicing, GDT) — and run the AML/CFT and governance programmes that hold afterwards. Trading as CamFinTech (legal entity CAMFINTECH CO., LTD pending registration).
We're structurally different from the firms most prospects compare us against:
Registered activity scope. CamFinTech is registered in Cambodia under KHNSIC-2015 codes 62010 (computer programming — integration development against the DPI rails), 62020 (computer consultancy, systems integration, regulatory-compliance advisory), 62090 (IT advisory, project management, data & analytics), 70200 (management consultancy, GRC, DPI integration advisory), and 85499 (professional training in FinTech, DPI, cybersecurity, regulatory compliance). All activities are delivered under the fee-only, never-operate, reserved-work discipline described below.
CamFinTech's defensible space is the layer between "the regulator" and "the build." Applications fail on AML/CFT, governance, capital planning, and documentation — not code. Most FinTechs put engineers on regulatory problems they were never trained for. The fix isn't more engineering — it's people who've worked the regulator's side of the desk.
Our people have worked inside the NBC, the NBFSA, the TSC, SERC and the GDT, and the NBFSA's own 2024–2028 FinTech plan makes developing this competency locally a national priority. We hire from the regulated-private side (mid-tier banks, MFIs, PSPs, accredited SPs) and from former-regulator advisers after a self-imposed cooling-off period; we do not engage serving officials.
Five rules that hold across every engagement, regardless of client or rail:
CamFinTech is newly established and has no completed client engagements to report. It publishes no case studies, no anonymised institutional references, and no quantified client outcomes, because it has none that could be evidenced. That will change only when a real engagement exists and the client has consented to it being described.
What is available to a procurement or third-party-risk reader today:
Two further standing notes. Pricing is indicative — every figure in the firm's materials is a planning estimate, validated by quote at scoping. Some mandates are anticipatory: the CamInvoice business-to-business mandate is phased and not yet gazetted, and the Personal Data Protection Law is not yet promulgated. The firm helps clients prepare ahead of both, and does not suggest that anyone is already in breach.
We hold our own operations to NBC's Technology and Cyber Risk Management Guidelines (TCRMG 2026) standards — voluntarily, as a non-BFI. Process competence isn't just what we sell. The compliance posture documentation set is available on request for BFI procurement conversations.
Most FinTechs in Cambodia that struggle to reach the national rails do not struggle on technology. They struggle because the requirements are prudential — compliance, governance and documentation rather than code — and that is a discipline an engineering organisation rarely has in-house. Foreign-owned operators arrive without local regulatory experience; local FinTechs put engineers on problems no engineer was trained to solve. Neither is a failing of the standard, which exists for good reason; it is a gap in who is available to meet it.
That gap is why William founded CamFinTech. Fuller professional history — prior work in Cambodian and ASEAN FinTech — is maintained on LinkedIn.