Company logo
About usExpertiseOur peopleFrameworksInsightsContactsالعربية
About usAbout usExpertiseExpertiseOur peopleOur peopleFrameworksFrameworksInsightsInsightsContactsContactsالعربيةالعربية
← InsightsArticles

Fintech Compliance in Dubai Mainland: Complete Guide

A permission granted in DIFC or ADGM does not authorise onshore activity.

Which authority a Dubai fintech answers to depends on what the product does with customer money: the Central Bank, the Securities and Commodities Authority, the emirate's virtual assets regulator, or the DFSA and FSRA inside the financial centres. This article explains how to work that out, what setting up the mainland entity and trade licence involves, and the financial crime controls an application has to evidence rather than merely document. It also covers customer data onshore and the contract terms that matter most: customer terms, sponsor bank and processor agreements, and outsourcing.

By Nour Attorneys / 24 August 2026

The activity decides the regulator

Fintech founders in Dubai usually ask the wrong question first. They ask which free zone to choose, or what the licence costs. The question that determines everything else is narrower: what, precisely, is the product doing? Holding customer money, moving it, lending it, exchanging it, advising on investments, offering tokens or simply passing data between a bank and a customer are different activities, and they answer to different authorities.

Broadly, payment services, stored value, money transfer and lending activity fall to the Central Bank of the UAE. Securities and investment activity, including crowdfunding and certain token offerings, falls to the Securities and Commodities Authority. Virtual asset activity carried on in Dubai outside the financial centre sits with the emirate's virtual assets regulator. Inside the Dubai International Financial Centre, the DFSA regulates; in Abu Dhabi Global Market, the FSRA does. Those two are common-law jurisdictions with their own courts and rulebooks, and a permission granted there does not authorise onshore activity.

Write down, in one paragraph and without marketing language, what your product does with customer money and customer data. Take that paragraph to the licensing conversation. Most costly mis-steps come from describing a regulated activity in terms designed to make it sound unregulated.

Setting up the mainland entity

A Dubai mainland fintech needs a trade licence from the Department of Economy and Tourism for the company, and the separate regulatory permission for the activity. The company itself is constituted under the Commercial Companies Law, Federal Decree-Law No. 32 of 2021, which replaced Federal Law No. 2 of 2015. That governs the constitutional documents, the appointment and removal of managers, and the duties of the people running the business. Regulators approve named individuals for compliance and money laundering reporting roles, so the articles, the internal delegations and the individuals notified to the authority must be consistent with each other.

Foreign ownership is generally available. Federal Decree-Law No. 26 of 2020, effective 1 June 2021, removed the general 51% UAE-national ownership requirement for mainland companies, and full foreign ownership is permitted for most mainland activities, subject to a list of activities with strategic impact. A branch of a foreign company remains a separate arrangement using a local service agent. Confirm the treatment of your specific activity before you agree a cap table with investors.

Financial crime controls are the licence condition that bites

For any business touching payments or customer funds, anti-money laundering compliance is not a policy document filed after launch. Expect to demonstrate, in the application itself, how you identify customers and verify their identity, how you screen against sanctions lists on onboarding and on an ongoing basis, how you monitor transactions and escalate what the monitoring flags, and how suspicious activity reports are filed through the national reporting system. Appoint a reporting officer who is genuinely available and genuinely senior, keep records of decisions not to report as well as decisions to report, and train the staff who actually onboard customers rather than only the compliance team.

The common failure is a well-drafted policy that nobody follows. Regulators test the process against the files, so build controls you can evidence.

Customer data

Fintech runs on personal data, and onshore that means Federal Decree-Law No. 45 of 2021. The DIFC and ADGM have their own data protection regimes, so a group operating on both sides of the line cannot run one undifferentiated policy. Decide before launch what you collect and why, how long it is retained, who inside the business can see it, what your processors and cloud providers may do with it, and on what basis it moves across borders. Put those terms into the contracts with your providers, not only into a privacy notice on the website.

If your model depends on access to customer banking data, the terms on which you obtain it — customer consent, the bank's own conditions, and what you may do with the data afterwards — should be settled in writing before the integration is built.

Contracts that reflect how the product actually works

Customer terms

Say what the service does and what it does not do. Set out fees, when they are charged and how they change. Explain who holds customer funds and where. Describe how a customer raises a complaint and how disputed transactions are handled. Terms drafted for another market and pasted in rarely survive contact with a UAE regulator or a UAE court.

Bank and provider agreements

Read the termination provisions in your sponsor bank or processor agreement before you sign, because a short notice period on the provider's side is an existential risk for a payments business. Look at liability caps, chargeback allocation, service levels and what happens to customer funds and data on exit.

Outsourcing

Outsourcing an operational function does not outsource responsibility for it. Where a third party performs onboarding, monitoring or processing, the contract needs audit rights, sub-contracting controls and a workable exit plan.

People and intellectual property

Staff are employed under Federal Decree-Law No. 33 of 2021, which replaced Federal Law No. 8 of 1980. For a technology business, the point to get right at the outset is ownership of what the team builds. Put clear assignment terms in employment contracts and in every contractor and agency agreement, including the ones signed before incorporation. Investors examine this in diligence, and a founder-era contractor with an unassigned contribution can hold up a funding round.

Tax, reporting and disputes

Corporate tax applies under Federal Decree-Law No. 47 of 2022 for financial years starting on or after 1 June 2023, at 0% up to AED 375,000 of taxable income and 9% above that. Describing the UAE as tax-free in an investor deck is inaccurate. VAT applies at 5% under Federal Decree-Law No. 8 of 2017 as amended by Federal Decree-Law No. 18 of 2022, and the treatment of a fintech fee model is not obvious, so have it assessed rather than assumed. Economic substance reporting was cancelled for financial years ending after 31 December 2022 by Cabinet Decision No. 98 of 2024, but obligations remain for the years from 2019 to 2022 and are still raised in diligence.

Commercial dealings sit within the framework of Federal Decree-Law No. 50 of 2022, which replaced Federal Law No. 18 of 1993. Decide deliberately where disputes go. An onshore contract with no arbitration clause goes to the Dubai Courts, which work in Arabic. Arbitration is governed by Federal Law No. 6 of 2018, amended in 2023; DIAC now administers cases that would previously have gone to DIFC-LCIA, abolished by Dubai Decree No. 34 of 2021, while the DIFC remains available as a seat, and ADCCAC was restructured as arbitrateAD from 2024. Name the institution, the seat and the language in the clause, so that a payments failure or a provider exit does not begin with an argument about forum before any financial dispute resolution can start.

Before you launch

  • Describe the activity plainly and confirm which authority licenses it.
  • Align the articles, delegations and notified individuals with each other.
  • Build financial crime controls you can evidence from customer files.
  • Settle data retention, processor terms and cross-border transfers before go-live.
  • Check termination, liability and fund-handling terms in provider contracts.
  • Secure intellectual property assignments from everyone who has written code.

For help scoping a fintech licence in Dubai or reviewing the contracts and controls behind an existing product, contact the Nour Attorneys team.

Schedule Your Consultation

Disclaimer: The information provided in this article is for general informational purposes only and does not constitute legal advice. Readers should seek professional legal advice tailored to their specific circumstances before making any decisions or taking any action based on the content of this article.

Nour Attorneys Team

Related Resources

Explore more of our insights on related topics:

  • Anti-money laundering obligations for UAE financial businesses
  • Data protection compliance under the UAE federal regime
  • Choosing between mainland Dubai, the DIFC and ADGM for a fintech
  • Payment provider and sponsor bank agreements
Contact Us

Location

Silver Tower Floor 20, Office 2003 Business Bay Dubai, United Arab Emirates (UAE)
Working hours
Mon–Fri: 9am — 6pm

Navigation

  • About Us
  • Expertise
  • Our People
  • ESG & Sustainability
  • Insights
  • Contacts

Social Media

  • LinkedIn
  • Instagram

Contacts

  • Telephone: +971 58 555 2999
  • WhatsApp: +971 58 555 2999
  • Chatbot
Founding Member - SKP Business Federation
INFO@NOURATTORNEYS.COM
Copyright © 2025 Nour Attorneys. All Rights Reserved
Privacy Policy
Call Us NowChat With Our Team On WhatsApp