M&A in UAE Regulatory Sandboxes: Fintech and Tech Acquisitions
Buying a sandbox-licensed fintech in the UAE turns on whether the regulator that granted the licence accepts the new owner, and on how much of the target's worth rests on an authorisation with caps, conditions and an expiry date.
A fintech holding a DIFC testing licence, a place in the ADGM RegLab or a Central Bank sandbox authorisation cannot simply be sold. The DFSA, FSRA or CBUAE must consent to the change of control and will test the buyer's fitness, governance and financial standing. What the licence's own caps and conditions do to the target's value, and whether an asset or share deal suits better, follow from that.
Reviewed by Mohamed Noureldin, Founder, Managing Partner & Senior Legal Consultant
M&A in UAE Regulatory Sandboxes: Fintech and Tech Acquisitions
The first question a buyer asks about a sandbox-licensed fintech is what the business is worth — the product, the customer list, the head start in a market nobody has properly served yet. The question that actually decides whether there is a deal is narrower, and usually gets asked far too late: will the regulator that granted the testing permission accept the buyer as the party now standing behind it?
A company holding a DIFC testing licence, a place in the Abu Dhabi Global Market (ADGM) RegLab, or an authorisation under the Central Bank of the UAE (CBUAE) sandbox is not an ordinary private company that happens to be regulated. Its permission was granted to a named firm, on stated conditions, for a defined period of testing, on the strength of who owned and ran it. Change the owners and that assessment is reopened. The Dubai Financial Services Authority (DFSA), the ADGM Financial Services Regulatory Authority (FSRA) and the CBUAE each require consent to a change in control, and each looks hardest not at the target it already supervises but at the buyer it does not yet know.
Related Services: Our regulatory compliance and mergers and acquisitions teams advise on transactions of this kind.
What a sandbox permission is, and what a buyer is buying
The three UAE sandbox regimes share a shape but sit under different supervisors and rulebooks, and the differences matter to a transaction.
The DIFC testing licence lets a fintech firm build and test financial products inside the DIFC under DFSA oversight. It permits operation at limited scale, within defined parameters and for a defined period, and it carries the DFSA's rules with it — including anti-money laundering (AML) and counter-terrorist financing (CTF) obligations, which bind a firm in testing as they bind any other authorised firm.
The ADGM RegLab operates under the FSRA and has been used heavily by firms working on digital assets, blockchain applications and payment products. A participant holds an authorisation with licensing conditions attached and restrictions on how it may operate, and the terms on which it eventually leaves the RegLab are part of what a buyer inherits.
The CBUAE sandbox is the broadest of the three, covering payment services, digital banking and other financial activity falling to the Central Bank. Participation brings capital adequacy, governance and reporting obligations, and the Central Bank's supervisory expectations sit alongside the sandbox conditions rather than being suspended by them.
What all three have in common is that the thing being sold is a conditional, time-limited permission to do a narrow set of activities, plus a route towards full authorisation that is not automatic. The software and the team are real, but they are not what makes the target a regulated business, and they are not what the regulator will examine.
The sandbox supervisor may also not be the only authority with an interest. A firm testing inside the DIFC can still touch activity that engages federal regulators — the Securities and Commodities Authority, for instance, where the product reaches into securities activity outside the financial free zone. Where a target's model spans several UAE jurisdictions, the acquisition plan needs a map of which authority governs which part, because a consent from one is not a consent from another.
The consent that decides the transaction
No sale of a sandbox-licensed entity completes on the parties' agreement alone. The change of control must be notified and approved, and the review is aimed at the buyer.
The DFSA has jurisdiction over the testing licence and must consent to a change in control or ownership of the holder. Its review covers three things a buyer should prepare for separately: whether the acquirer and the people it will put in place are fit and proper; whether the governance it proposes is capable of running a regulated firm; and whether it has the financial strength to keep the firm viable through the rest of the testing period and beyond. A regulated financial institution evidences the first and third more easily than a private investor or an operating technology group does.
The FSRA applies its own approval process to acquisitions affecting RegLab participants. Its focus is continuity — whether the incoming owner can keep the firm compliant with the conditions attached to its authorisation, and whether the test the RegLab admitted will still be run. That has a practical consequence buyers often miss: if the acquisition changes what the business does, the authorisation may need to be amended or reassessed, and the plan the buyer wrote for its investment committee is the same plan the regulator will read.
The CBUAE's approval is decisive where the target sits in its sandbox. The Central Bank examines the acquirer's financial soundness, its compliance culture and what it intends to do with the target. Gaps in governance or compliance history can produce a refusal or, more often, an approval loaded with conditions the buyer must live with.
Two procedural points shape the timetable. First, sequencing: regulators may require notification before the transaction is announced publicly or completed, so signing, announcement and closing have to be ordered around the filing rather than the reverse. Getting that wrong causes delay and can become a supervisory issue in itself. Second, confidentiality: the filings describe the target's technology and business model in detail, so confidentiality undertakings and a controlled disclosure plan belong in place before the first regulatory conversation.
Early engagement is worth more here than in most transactions. A pre-filing discussion that surfaces a concern about, say, the proposed board can be answered with a revised governance package before the formal application goes in. The same concern found after filing can put the licence in question — as it does for the buyer whose named directors turn out not to satisfy the DFSA's fit and proper expectations, and who must rebuild the post-closing governance structure and evidence its own compliance record before the deal can move.
What the licence's own limits do to the price
Sandbox permissions are narrow by design, and the limits written into the target's licence are the most under-examined figures in the transaction.
The conditions typically restrict the scale and the audience of the test: caps on transaction volumes, limits on which categories of customer may be onboarded, geographic constraints on where the service may be offered. Each of those caps sets a ceiling on what the target can earn while the permission is what it is. A firm running at or close to its cap is not a firm growing quickly — it is a firm that has stopped growing until something changes.
The second figure is the time left. Sandbox admission runs for a testing period, and the value in most of these targets sits on the far side of it, in the full authorisation the firm hopes to hold afterwards. That transition has to be applied for and earned; it is not a renewal by default, and the standards a firm is assessed against can move while it tests. A buyer pricing a target on post-sandbox revenue is pricing an outcome no regulator has yet granted.
The useful discipline is to split the valuation in two. One part is what the business has demonstrated inside the constraints it operates under — real customers, real volumes, real unit economics, however small. The other is what it can only earn once the caps come off. The first supports a price at signing. The second belongs in earn-out or deferred consideration, tied to the licensing outcome that must occur before it can be realised.
Due diligence: read the licence file first
In a conventional acquisition the licence is a schedule item. Here it is the main document, and the exercise starts with the authorisation, its conditions, and the correspondence between the firm and its supervisor.
That correspondence is where the real history sits: questions asked, undertakings given, breaches self-reported, remediation promised and whether it was delivered. Because sandbox participants operate under close supervision, a compliance failure is not only a financial exposure — it is a threat to the permission the buyer is paying for. Contingent liabilities arising from regulatory findings need to be identified and priced, and the target's governance and record-keeping examined for whether they survive the same scrutiny under a new owner.
Intellectual property deserves closer attention in fintech than the standard checklist gives it. Core code is often written with contractors or development partners on informal terms, and ownership that was never properly assigned surfaces at the worst moment. Data protection is the companion issue: where customer data is held, whether the arrangement satisfies local requirements on data handling and localisation, and whether the consents the target collected cover what the buyer intends to do next.
Cybersecurity and operational resilience
Systems built to prove a concept are rarely built to withstand attack. A technical audit of the target's infrastructure, vulnerabilities and incident response arrangements belongs in the diligence scope, not the post-closing integration plan.
The legal dimension is that a security failure at a regulated firm is also a licensing event. The DFSA's rules carry cybersecurity obligations, and a firm that cannot meet them faces enforcement as well as loss. Warranties and indemnities should address cybersecurity exposure specifically, and where the audit finds weaknesses, remediation should be a documented post-closing obligation with a timetable, not a general commitment to improve.
An illustration
Take a blockchain payments business in the ADGM RegLab. Its authorisation caps the value of transactions it may process during testing and limits onboarding to defined categories of investor. Diligence shows it is close to both limits, and that its application for full authorisation has slowed because the FSRA's licensing standards moved since it was admitted. Its smart contract templates were built with outside developers under agreements that do not clearly assign ownership, and its customer data sits on distributed nodes, some outside the UAE.
None of that necessarily stops the deal. It changes its shape: consideration split so the part resting on full authorisation is paid only if it arrives, specific indemnities for the IP and data findings, a pre-closing tidy-up of the developer agreements, and a conversation with the FSRA before signing rather than after.
Asset or share: which structure the licence permits
The structuring choice here is unusually constrained, because the permission attaches to the entity.
A share purchase keeps the licensed company intact. The authorisation stays where it is, the testing continues, customer contracts and supplier arrangements are untouched, and the regulatory relationship is preserved. The price of that continuity is that the buyer takes the company's entire history with it — every past breach, every unresolved supervisory question, every contingent claim. That is what the warranty and indemnity package is for, and in a sandbox target it should be drafted around the licence: warranties that the authorisation is valid and in good standing, that its conditions have been complied with, that all required regulatory approvals for the transaction have been obtained, and that nothing has been notified or threatened that could put the permission at risk.
An asset purchase leaves the licensed entity behind. It attracts a buyer that wants the technology and the team but not the compliance history, or that already holds the authorisation it needs. But the permission generally does not travel with the assets, so the buyer either operates under its own licence or applies afresh — and applying afresh means the regulated activity stops in the interim. Customer contracts need novation and, in a financial services business, often customer consent. That disruption is real and should be modelled before the structure is chosen.
In practice the decision follows from one fact: whether the buyer is already authorised to do what the target does. A regulated acquirer can often take the assets. An unregulated one buys the shares, because it is buying the permission.
Change-of-control clauses elsewhere in the target's contracts should be pulled at the same time. Key supplier agreements, technology licences and employment terms may each carry provisions triggered by a change in ownership, and the consents or novations they require run on the same timetable as the regulatory approval, not after it.
Terms that hold the deal together while the regulator decides
Because approval sits outside the parties' control, the documents have to work for a period during which nobody knows the answer.
Regulatory consent belongs among the conditions precedent, with a long-stop date and a clear statement of what happens if it is not met — who may walk away, whether either side owes anything, and who bears the cost of the wait. Consent given subject to conditions needs its own treatment: the agreement should say which conditions the buyer must accept and which are onerous enough to release it.
Between signing and closing, the target should be held to interim covenants that keep the licence safe: no breach of the sandbox conditions, no change to the tested business model, no change of directors or senior officers without consent, and prompt notice of any contact from the regulator. A target that damages its own authorisation while the buyer waits defeats the transaction.
Consideration mechanics can absorb the uncertainty rather than fight it. Earn-outs and milestone payments tied to full authorisation, or to the lifting of specific caps, align both sides on the outcome that matters. Escrow secures the indemnities covering regulatory exposure, giving the buyer a fund to draw on if a historic compliance problem surfaces after closing.
Staged structures are sometimes used to manage the timetable — a minority position first, with the balance acquired once approval is in hand, or a joint venture while the target completes its transition out of the sandbox. These need care: whether a given stake amounts to a change in control requiring consent is a question for the applicable rulebook, and a structure designed to avoid an approval is more likely to attract attention than to escape it.
After closing: keeping the permission and getting past it
The transaction is not finished when the consideration moves. The buyer holds a permission that can be lost, and a transition to full authorisation still to be earned.
The compliance programme comes first. AML and CTF controls, cybersecurity arrangements and data protection practices must meet the supervisor's expectations from the first day of the new ownership, not from the end of an integration project. Where diligence found weaknesses, remediation should already be running.
Governance follows: compliance officers with the right approvals in place, internal audit that actually reports, and clear lines from the operating business to the board and from the board to the regulator. Where the buyer is a larger group, the target's reporting must reach group level without breaking the direct relationship the supervisor expects with the licensed entity.
Operational integration is where good intentions cause damage. Migrating the target onto group systems, changing providers or altering how the product works can each touch a condition of the authorisation. Check every integration step against the licence before scheduling it, and raise material changes with the supervisor in advance.
Reporting is continuous. Sandbox supervisors expect regular information on operational metrics, risk and compliance developments, and the cadence and content are set by the authorisation itself. Internal reporting should be built to produce those submissions accurately and on time, with someone named as responsible for the regulatory relationship.
There is a human dimension with regulatory consequences. Firms in testing are small, fast and informal, and the controls a corporate buyer imposes can drive out the people who built the product. Keeping the team is not a soft objective: the application for full authorisation turns on operational resilience, compliance maturity and financial soundness, and all three rest on the people running the business.
Conclusion
Buying a fintech in a UAE regulatory sandbox is an acquisition in which the regulator is effectively a party. The DFSA, the FSRA and the CBUAE each control whether the permission that gives the target its value survives the change of ownership, and each assesses the buyer's fitness, its governance and its financial standing before deciding. The conditions written into that permission — the volume caps, the customer restrictions, the length of the testing period — set what the business can earn until something wider replaces it. And the choice between a share and an asset deal is largely settled by whether the buyer needs the permission or already holds one of its own.
Handled in that order — regulator first, price second — these transactions are entirely workable. Handled in reverse, they produce agreed prices that no consent supports.
Nour Attorneys advises acquirers and founders on transactions involving DIFC, ADGM and Central Bank sandbox participants, from the first regulatory conversation through change-of-control approval and the transition to full authorisation.
Disclaimer
This article is for informational purposes only and does not constitute legal advice.
Additional Resources
- Mergers & Acquisitions Services
- Corporate Law Services
- Due Diligence Services
- Contract Drafting Services
Contact Nour Attorneys
To discuss an acquisition involving a sandbox-licensed fintech, contact Nour Attorneys. Our Mergers & Acquisitions Dubai page sets out how we work.
Additional Resources
More of our insights on related topics: