← Insights

ADGM Fintech Regulatory Sandbox Application

What the FSRA requires before testing starts, what testing involves, and what full authorisation demands afterwards

How the FSRA’s RegLab lets firms test innovative financial products under FSRA supervision, with certain regulatory requirements relaxed. It sets out the eligibility criteria, the stages of an application and the documents applicants must provide, then covers the testing period, the FSRA’s power to cancel the permission, and migration to full authorisation under the FSMR.

Reviewed by Mohamed Noureldin, Founder, Managing Partner & Senior Legal Consultant

A firm with a financial product built on new technology, or on a novel application of existing technology, can test it in the FSRA’s Regulatory Laboratory (RegLab). It can do so without immediately complying with the full scope of regulatory obligations that apply to licensed entities. Testing takes place under the supervision of the ADGM Financial Services Regulatory Authority (FSRA). Entry depends on the application, which the FSRA assesses against the eligibility and authorisation criteria applicants must satisfy to be authorised as FinTech Participants. For firms that complete testing successfully, the next step is to migrate, if eligible, to the full authorisation and supervisory regime under the FSMR.

Certain requirements are relaxed, on conditions

ADGM is an international financial centre in Abu Dhabi, operating under a distinct legal framework separate from the UAE’s mainland jurisdiction.

The RegLab framework is set out in FSRA guidance issued under section 15(2) of the Financial Services and Markets Regulations 2015. The requirements that apply to participants may be adapted from existing regulations, including the FSMR, and from the FSRA Rules. The sandbox’s framework permits firms to test innovative financial products, services or business models that involve new technology or novel applications of existing technology. It allows temporary relaxation of certain regulatory requirements, provided that risks are managed and consumer protection is maintained.

The FSRA has had regard to the Financial Action Task Force (FATF) Recommendations in making its anti-money laundering rules, and has closely aligned those rules with them where necessary and appropriate. Its Prudential – Investment, Insurance Intermediation and Banking Rulebook (PRU) outlines the minimum capital requirements that an Authorised Person should meet, consistent with Pillar 1 of the Basel Accord.

Eligibility: the innovation, its benefit and the applicant’s resources

Applicants must satisfy eligibility and authorisation criteria to be authorised as FinTech Participants. Among other things, the applicant must demonstrate that:

  • the proposal promotes FinTech innovation, in terms of the business application and deployment model of the technology;
  • the proposal has the potential to promote significant growth, efficiency or competition in the financial sector, promote better risk management solutions and regulatory outcomes, or improve the choices and welfare of clients;
  • it has adequate and appropriate resources, including financial resources, to develop and test the proposal;
  • it can detail the safeguards put in place and show how they are appropriate to the proposal, the risks it poses and the clients likely to be affected;
  • it can clearly define the proposal’s test parameters, control boundaries, key milestones and intended outcomes.

From informal discussion to exit

The process is structured to balance regulatory scrutiny with help for fintech innovation. It consists of multiple stages:

  1. Pre-application engagement. Applicants are encouraged to engage with the FSRA through informal discussions, to clarify regulatory expectations and assess whether the innovation suits the sandbox.
  2. Formal application submission. Applicants submit a detailed application package comprising a business plan, technology description, risk assessment, compliance framework and proposed testing parameters.
  3. Assessment and review. The FSRA reviews the application, focusing on innovation, risk management, consumer protection and regulatory compliance.
  4. Approval and permission. Successful applicants are granted an FSRA Financial Services Permission to carry on the Regulated Activity of Developing Financial Technology Services within the RegLab, with specific conditions tailored to the testing environment.
  5. Testing and monitoring. The applicant conducts the testing under FSRA supervision and submits periodic reports on progress, risks and compliance.
  6. Exit and transition. At the end of the permission’s validity period, or earlier if the size, scale or progress of the proposal warrants, the firm exits the RegLab. If eligible, it may migrate to the full authorisation and supervisory regime under the FSMR.

What goes into the application file

Applicants must provide full documentation to satisfy FSRA requirements. The table shows what each document contains and what it is for.

Document typeDescriptionPurpose
Business planDetailed plan outlining business model, objectives and market strategyDemonstrates viability and innovation
Technology descriptionTechnical details of the product or service and the underlying technologyAssesses innovation and operational risks
Risk management frameworkPolicies and procedures to identify, mitigate and monitor risksEnsures risk controls and consumer protection
Compliance and AML/CFT policiesProcedures to comply with anti-money laundering and counter-terrorist financing lawsDemonstrates regulatory compliance
Financial projectionsBudget, funding sources and financial sustainability analysisAssesses financial viability
Testing planDefined scope, timeline, objectives and metrics for sandbox testingHelps with monitoring and assessment

Cost and length of testing

The permission granted under the RegLab has a validity period of up to two years. That period may be extended in exceptional circumstances only, at the FSRA’s discretion. Fees and timelines are communicated during the application process and are subject to periodic updates.

Why test inside the sandbox

By engaging directly with the FSRA in a controlled environment, firms can accelerate product development, validate business models and gain valuable regulatory insights. The sandbox reduces time-to-market and mitigates legal risks associated with untested innovations.

The sandbox also supports cross-border collaboration and international partnerships. Given ADGM’s position as a global financial centre, firms can use sandbox-tested innovations to expand into other markets within the UAE and globally, subject to applicable licensing and regulatory approvals.

The permission can be cancelled during testing

Firms must also consider the stringent compliance obligations inherent in the sandbox framework. Despite the regulatory flexibility, the FSRA maintains rigorous oversight, particularly concerning consumer protection, market integrity and AML/CFT compliance. The FSRA may cancel the permission on its own initiative if, for example, the firm is failing to satisfy the Threshold Conditions.

What full authorisation demands

At the end of testing, a RegLab participant may migrate to the full authorisation and supervisory regime under the FSMR and offer its FinTech solution on a broader scale, subject to ongoing regulatory oversight. Alternatively, it may employ an exit strategy.

To be eligible to migrate, the participant must demonstrate to the FSRA that it has achieved its intended test outcomes under the RegLab and continues to be fit and proper to be an Authorised Person in the ADGM. Firms should proactively develop compliance frameworks that can scale beyond the sandbox environment.

ADGM’s regulatory environment is continuously evolving, and the FSRA updates sandbox policies to align with global fintech developments and emerging risks. Firms must therefore maintain active engagement with regulators and legal counsel to stay compliant and strategically agile.

Related services and further reading

Call Us NowChat With Our Team On WhatsApp